{
  "schema_version": "0.1",
  "records": [
    {
      "id": "EV-056",
      "type": "validation",
      "summary": "Verified REQ-084 and v0.8.0 delegated reporting: typed JSON/CLI policy, deterministic privacy-safe bundles, strict source-backed result validation, fallbacks, UTCP discovery, installer and seven-mirror delivery all pass; PRD Plugin makes no model call and AI-Collab remains the execution boundary.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests -v",
          "outcome": "ok",
          "tests_run": 677,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/local_workflow_check.py",
          "outcome": "ok"
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.8.0; python scripts/release_check.py; python scripts/state_consistency_check.py --repo-root .",
          "outcome": "ok"
        },
        {
          "command": "configured seven-validator on-stop drift re-audit via scripts.drift_monitor._run_validator",
          "outcome": "ok",
          "validators": 7,
          "findings": 0
        }
      ],
      "source_ids": [
        "REQ-084",
        "TRK-070",
        "PRD-003",
        "ARCH-003",
        "IMP-003",
        "HLT-005"
      ],
      "artifacts": [
        "scripts/prd_reporting.py",
        "scripts/prd_config.py",
        "scripts/prd_tools.py",
        "utcp.json",
        "commands/prd-report.md",
        "wiki/integrations/delegated-reporting.md"
      ],
      "recorded_at": "2026-07-12"
    },
    {
      "id": "EV-055",
      "type": "validation",
      "summary": "Verified REQ-083 and v0.7.1: 656 unit tests pass; local_workflow_check completes; gap, release, state-consistency, and PRD gates are clean; all seven configured drift-hook validators return ok with zero findings; wiki reports 19 current/indexed articles and the ingest manual is conformant.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests -v",
          "outcome": "ok",
          "tests_run": 656,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/local_workflow_check.py",
          "outcome": "ok"
        },
        {
          "command": "configured seven-validator drift-hook re-audit via scripts.drift_monitor._run_validator",
          "outcome": "ok",
          "validators": 7,
          "findings": 0
        }
      ],
      "source_ids": [
        "REQ-083",
        "TRK-067",
        "HLT-003"
      ],
      "artifacts": [
        "scripts/prd_self_audit.py",
        "tests/test_prd_self_audit.py",
        "wiki/index.md",
        ".prd_plugin/state/health.json"
      ],
      "recorded_at": "2026-07-11"
    },
    {
      "id": "EV-001",
      "type": "validation",
      "summary": "Verified v0.5.30 opencode adapter implementation: 130/130 unit tests pass; state consistency check returns 0 errors; gap_audit.py --target-version 0.5.30 reports no findings; release_check.py reports no findings; request_report, prd_doctor, and message_check all run successfully.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 130,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root .",
          "outcome": "ok",
          "errors": 0,
          "warnings": 0
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.5.30 --no-fail",
          "outcome": "ok",
          "findings": "None"
        },
        {
          "command": "python scripts/release_check.py --output request-report/release-hygiene.md --no-fail",
          "outcome": "ok",
          "findings": "None"
        },
        {
          "command": "python scripts/request_report.py --config .prd_plugin/config.json --format markdown --output request-report/request-report.md",
          "outcome": "ok"
        },
        {
          "command": "python scripts/prd_doctor.py --repo-root . --format json --output request-report/prd-doctor.json",
          "outcome": "ok"
        },
        {
          "command": "python scripts/prd_install_skills.py --repo-root . --target-agent both --dry-run",
          "outcome": "ok",
          "would_install": 20
        }
      ],
      "source_refs": [
        "REQ-002",
        "TRK-001"
      ],
      "linked_ids": [
        "REQ-002",
        "TRK-001",
        "CHG-001"
      ],
      "created_from_session": "SES-002",
      "created_by_agent": "AGENT-001",
      "confidence": "high",
      "status": "verified",
      "created_at": "2026-06-16"
    },
    {
      "id": "EV-002",
      "type": "validation",
      "summary": "Historical verification record for an integration removed by user request.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 146,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root .",
          "outcome": "ok",
          "errors": 0,
          "warnings": 0
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.5.31 --no-fail",
          "outcome": "ok",
          "findings": "None"
        },
        {
          "command": "python scripts/prd_doctor.py --repo-root .",
          "outcome": "ok",
          "errors": 0,
          "warnings": 0
        }
      ],
      "source_refs": [
        "REQ-001",
        "TRK-007"
      ],
      "linked_ids": [
        "REQ-001",
        "CHG-002"
      ],
      "created_from_session": "SES-003",
      "created_by_agent": "AGENT-001",
      "confidence": "high",
      "status": "verified",
      "created_at": "2026-06-16"
    },
    {
      "id": "EV-003",
      "type": "validation",
      "summary": "Verified the audit-driven additions to PRD Plugin v0.5.32: 175 unit tests passed; state consistency, gap audit, release check, doctor, and self-audit passed.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 175,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root .",
          "outcome": "ok",
          "errors": 0,
          "warnings": 0,
          "infos": 0
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.5.32 --no-fail",
          "outcome": "ok",
          "findings": "None"
        },
        {
          "command": "python scripts/release_check.py --no-fail",
          "outcome": "ok",
          "findings": "None"
        },
        {
          "command": "python scripts/prd_doctor.py --repo-root .",
          "outcome": "ok",
          "errors": 0,
          "warnings": 0
        },
        {
          "command": "python scripts/prd_self_audit.py --repo-root . --format markdown",
          "outcome": "ok (0 AGENTS.md/CLAUDE.md rules, 43 debt markers detected in the plugin source itself)"
        }
      ],
      "source_refs": [
        "REQ-001",
        "TRK-022"
      ],
      "linked_ids": [
        "REQ-001",
        "TRK-014",
        "TRK-015",
        "TRK-016",
        "TRK-017",
        "TRK-018",
        "TRK-019",
        "TRK-020",
        "CHG-003"
      ],
      "created_from_session": "SES-004",
      "created_by_agent": "AGENT-001",
      "confidence": "high",
      "status": "verified",
      "created_at": "2026-06-16"
    },
    {
      "id": "EV-004",
      "type": "validation",
      "summary": "Verified the REQ-029 Codex Stop-hook fix: the guarded hook exits 0 with no error when archive_automation_session.py is absent and runs it when present, on both POSIX (sh -c) and Windows (cmd /c if exist); the full unit suite and state consistency pass.",
      "commands": [
        {
          "command": "sh -c 'f=.prd_plugin/scripts/archive_automation_session.py; [ -f \"$f\" ] && python \"$f\" || exit 0'",
          "outcome": "ok",
          "note": "exit 0 when absent; runs when present"
        },
        {
          "command": "cmd /c \"if exist .prd_plugin\\scripts\\archive_automation_session.py (python ...) else (exit 0)\"",
          "outcome": "ok",
          "note": "exit 0 when absent; runs when present"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 298,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-029",
        "CHG-007"
      ],
      "limitations": "Hook behavior validated by running the guarded command lines directly, not by a live Codex session stop. Skill path-mismatch text was documented, not rewritten."
    },
    {
      "id": "EV-005",
      "type": "validation",
      "summary": "Verified REQ-031 (v0.5.56): the full unit suite passes (334 tests, incl. new test_decision_policy, test_workflow_consistency, test_prd_gate, test_helper_scripts, test_method_docs); prd_gate proves each enforced rule fails on a violation and a clean repo passes; gap audit (0.5.56), state consistency, and release hygiene are clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 334,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check",
          "outcome": "ok"
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root .",
          "outcome": "ok"
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.5.56",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-031",
        "TRK-023",
        "CHG-008"
      ],
      "limitations": "Skill behavior is validated by content/structure tests and the gate, not by a live multi-host agent run."
    },
    {
      "id": "EV-006",
      "type": "validation",
      "summary": "Verified REQ-032 (v0.5.57): 343 unit tests pass incl. new test_grounding_estimation (CLAUDE.md presence, AGENTS/CLAUDE rules, timescale gate fires on ranges and not on complexity ratings) and updated test_method_docs; gap audit (0.5.57), state consistency, prd_gate, and release hygiene clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 343,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check",
          "outcome": "ok"
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.5.57",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-032",
        "TRK-024",
        "CHG-009"
      ],
      "limitations": "Timescale check is warning-only and scoped to requests/tracking/decisions text fields."
    },
    {
      "id": "EV-007",
      "type": "validation",
      "summary": "Verified REQ-033 (v0.5.58): 347 unit tests pass incl. new test_change_request (skill content, downstream_runtime + required, router wiring, mirror parity); gap audit (0.5.58), state consistency, prd_gate, and release hygiene clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 347,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check",
          "outcome": "ok"
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.5.58",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-033",
        "TRK-025",
        "CHG-010"
      ],
      "limitations": "Skill validated by content/router tests, not a live multi-host agent run."
    },
    {
      "id": "EV-008",
      "type": "validation",
      "summary": "Verified REQ-034 (v0.5.59): 352 unit tests pass incl. new test_claude_nudge (hub .claude/skills parity with opencode, settings.json wires SessionStart+UserPromptSubmit to the nudge, CLAUDE.md carries the routing map); nudge script prints the router reminder; gap audit (0.5.59), state consistency, prd_gate, release hygiene clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 352,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python .claude/hooks/prd_nudge.py",
          "outcome": "ok"
        },
        {
          "command": "python scripts/prd_gate.py check",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-034",
        "TRK-026",
        "CHG-011"
      ],
      "limitations": "The nudge injects context; it cannot force skill invocation. Real-world effect must be observed in a fresh Claude session."
    },
    {
      "id": "EV-009",
      "type": "validation",
      "summary": "Verified REQ-035 (v0.5.60): 358 unit tests pass incl. new test_skill_usage (logger records Skill invocations, ignores other tools, never crashes on bad stdin; report counts skills, summarizes per session, flags shipped work with no verification/TDD skill use); gap audit (0.5.60), state consistency, prd_gate, release hygiene clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 358,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-035",
        "TRK-027",
        "CHG-012"
      ],
      "limitations": "Capture is Claude Code-specific (PostToolUse on the Skill tool); Codex/opencode need their own capture. The report is host-agnostic. Session join is by timestamp/host-session, not the SES-* ids."
    },
    {
      "id": "EV-010",
      "type": "validation",
      "summary": "Verified REQ-036 (v0.5.61): 360 unit tests pass incl. new AutoReportHookTests (settings wire Stop -> prd_session_report; the wrapper regenerates the report file from a seeded log); gap audit (0.5.61), state consistency, prd_gate, release hygiene clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 360,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-036",
        "TRK-028",
        "CHG-013"
      ],
      "limitations": "Stop fires per-turn, so only the fast skill-usage report is auto-generated; request/doctor reports remain on-demand or in CI."
    },
    {
      "id": "EV-011",
      "type": "validation",
      "summary": "Verified REQ-037 (v0.5.62): 367 unit tests pass incl. new test_slash_commands (prd_hooks disable/enable/status round-trip + idempotence; command files present in all 3 locations and invoke the right scripts); gap audit (0.5.62), state consistency, prd_gate, release hygiene clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 367,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-037",
        "TRK-029",
        "CHG-014"
      ],
      "limitations": "Slash commands are Claude Code-specific. Hook enable/disable takes effect in the next session (hooks load at session start)."
    },
    {
      "id": "EV-012",
      "type": "validation",
      "summary": "Verified REQ-038 (v0.5.64): 372 unit tests pass incl. new test_tracking_commands (prd_status build over a seeded repo + empty-repo safety; the 5 command files present in all 3 locations and invoking the right scripts/skills; prd_status.py downstream_runtime). gap audit (0.5.64), state consistency, and prd_gate clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 372,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-038",
        "TRK-030",
        "CHG-016"
      ],
      "limitations": "Slash commands are Claude Code-specific. prd_status.py reads optional state files and degrades gracefully when they are absent."
    },
    {
      "id": "EV-013",
      "type": "validation",
      "summary": "Verified REQ-039 (v0.5.65): full unit suite passes incl. new ParallelWorkRulesTests (AGENTS.md hub+skeleton carry the section, single-writer rule, registry path, 'does not orchestrate'; CLAUDE.md hub+skeleton carry the bullet). gap audit (0.5.65), state consistency, prd_gate clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok"
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.5.65",
          "outcome": "ok"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-039",
        "TRK-031",
        "CHG-017"
      ],
      "limitations": "Rules are advisory guidance in the host-read files; they are not mechanically enforced beyond the duplicate-ID/state-consistency gates that catch concurrent-write damage after the fact."
    },
    {
      "id": "EV-014",
      "type": "validation",
      "summary": "Verified REQ-040 (v0.5.66): 378 unit tests pass incl. reporting.md content guards, AGENTS.md/CLAUDE.md reporting-rule guards, and a 7-mirror check that the decision-policy skill carries 'continuing the planned work is not a decision'. gap audit (0.5.66), state consistency, prd_gate clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 378,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-040",
        "TRK-032",
        "CHG-018"
      ],
      "limitations": "These are advisory rules in host-read files and the skill; they are not mechanically enforced (no reliable text-gate for 'led with IDs' or 'asked in autonomous'). Compliance depends on the agent reading AGENTS.md/CLAUDE.md and the skill."
    },
    {
      "id": "EV-015",
      "type": "validation",
      "summary": "Verified REQ-041 (v0.5.67): 386 unit tests pass incl. new test_prd_graph (node/edge build, impact+provenance traversal over a BR->PRD->ARCH->IMP->EV chain, gap detection of a requirement with no task, AI-Collab cause/effect export shape, set-auto config flip, command files in 3 locations, downstream_runtime registration, config flag default false). Live run on hub state: 175 nodes, 351 edges. gap audit (0.5.67), state consistency, prd_gate clean; graph output is under gitignored .prd_plugin/local/.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 386,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_graph.py --out .prd_plugin/local/traceability-graph.json",
          "outcome": "ok"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-041",
        "TRK-033",
        "CHG-019"
      ],
      "limitations": "Gap rules cover requirement->task and task->validation/evidence by ID prefix; other gap types are not yet checked. Auto-refresh runs only in the Claude Code Stop hook (other hosts regenerate on demand). AI-Collab ingestion of the exported edge list was not tested against a live AI-Collab instance."
    },
    {
      "id": "EV-016",
      "type": "validation",
      "summary": "Verified REQ-042 (v0.5.68): 397 unit tests pass incl. new test_stop_guard (continue when autonomous+open goal; stop when not autonomous / no goal / flag off / paused / cap reached; errors default to stop; continue reason teaches the pause escape; guard registered in Stop hooks hub+skeleton; config defaults; hook mirrored). gap audit (0.5.68), state consistency, prd_gate clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 397,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-042",
        "TRK-034",
        "CHG-020"
      ],
      "limitations": "Live Stop-hook continuation was not exercised inside a real Claude Code autonomous session (decide()/wiring are unit-tested; end-to-end block behavior depends on the host honoring {decision:block} and any built-in consecutive-block cap). 'Active goal' = an open TRK-* record; a stale-open TRK would keep continuing until the cap or a pause. Consent-floor safety relies on the agent writing the pause marker / filing a blocker when it needs the user."
    },
    {
      "id": "EV-017",
      "type": "validation",
      "summary": "Verified REQ-043 (v0.5.69): 410 unit tests pass incl. rewritten real-schema prd_graph fixture, new graph CLI/mermaid/dangling/orphan/unreadable/empty-repo tests, and new stop-guard main() tests (cumulative counter, cap clears, pause cleared, malformed stdin). Live hub graph after fix: orphans 75->0, false incomplete 25->0, dangling now honest (22 = un-persisted brainstorm + known old refs). gap_audit (0.5.69), state consistency, prd_gate clean; prd_gate decision CLI re-checked with the new mutually-exclusive flag.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 410,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_graph.py --gaps",
          "outcome": "ok"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-043",
        "TRK-035",
        "CHG-021"
      ],
      "limitations": "Deferred: hook interpreter portability (python vs python3) needs an installer change, tracked as a separate task. traceability_sync_auto.py still swallows malformed JSON (lower-priority first-pass helper). Live Stop-hook block-and-continue still not exercised in a real autonomous Claude Code session."
    },
    {
      "id": "EV-018",
      "type": "validation",
      "summary": "Verified REQ-044 (v0.5.70): prd_install now writes an install-time-detected, runnable interpreter into generated .claude/settings.json hooks. RED->GREEN TDD: HookInterpreterTests failed on missing _detect_hook_interpreter import, pass after impl. Full suite 417 tests OK; release_check (base 0.5.68 -> head 0.5.70) Findings: None; gap_audit 0.5.70 None; state_consistency ok; local_workflow_check exit 0. End-to-end install on this host rewrote all 5 hook commands `python` -> `python3` (claude_settings={'interpreter':'python3','patched':true,'commands':5}); hub + skeleton settings.json left on `python`.",
      "created_from_session": "SES-CLAUDE-20260625",
      "created_by_agent": "AGENT-CLAUDE",
      "created_at": "2026-06-25",
      "source_refs": [
        "REQ-044",
        "TRK-036",
        "scripts/prd_install.py",
        "tests/test_prd_install.py"
      ],
      "commands": [
        "python -m unittest discover -s tests  -> Ran 417 tests OK",
        "python scripts/release_check.py  -> Findings: None (head 0.5.70)",
        "python scripts/gap_audit.py --target-version 0.5.70  -> Findings: None",
        "python scripts/state_consistency_check.py --repo-root .  -> ok",
        "python scripts/local_workflow_check.py  -> exit 0"
      ]
    },
    {
      "id": "EV-019",
      "type": "validation",
      "summary": "Verified REQ-045 (v0.5.71): 423 unit tests pass incl. new nudge guard (no 'project-session-close' string; carries 'never tell the user to wrap up') and a 'never nag to stop' guard across reporting.md + AGENTS.md + CLAUDE.md. gap audit (0.5.71), state consistency, prd_gate clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 423,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-045",
        "TRK-037",
        "CHG-023"
      ],
      "limitations": "Advisory + the nudge hook (Claude Code). Other hosts get the AGENTS.md/skill rules but not the hook text. Can't mechanically detect a context-pressure wrap-up; removing the bait + explicit rule is the lever."
    },
    {
      "id": "EV-020",
      "type": "validation",
      "summary": "Verified REQ-046 (v0.5.72): 424 unit tests pass incl. new DecisionQualityBarTests asserting the bar + all 7 terms appear in AGENTS.md and CLAUDE.md (hub + skeleton). gap audit (0.5.72), state consistency, prd_gate clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 424,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-046",
        "TRK-038",
        "CHG-024"
      ],
      "limitations": "Placement change only; like all advisory rules, whether an agent applies the bar remains unobservable from logs."
    },
    {
      "id": "EV-021",
      "type": "validation",
      "summary": "Verified REQ-047 (v0.5.73): 426 unit tests pass incl. new TDD tests (force install does not clobber an existing downstream README; install does not plant the plugin README) which failed before the fix. gap audit (0.5.73), state consistency, prd_gate clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 426,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-047",
        "TRK-039",
        "CHG-025"
      ],
      "limitations": "Repos already clobbered by a prior --force keep the plugin README until restored from git (the installer will no longer touch it). The plugin's own README still lives at the hub root for npm/GitHub."
    },
    {
      "id": "EV-022",
      "type": "validation",
      "summary": "Verified REQ-048 (v0.5.74): 438 unit tests pass incl. new test_precommit_gate (is_git_commit detection incl. `git -c k=v commit` and excluding `git config commit.gpgsign`; flag gating; warnings don't block; main() returns 2 on a gate error via stub, 0 when clean/disabled/non-commit/missing-gate; PreToolUse wiring hub+skeleton; templates flag default false). gap audit (0.5.74), state consistency, prd_gate clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 438,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-048",
        "TRK-040",
        "CHG-026"
      ],
      "limitations": "Forces commit-output cleanliness, not skill invocation (can't be forced) and not quality (a token artifact can satisfy the gate). Claude Code-specific (PreToolUse). Live block-on-commit not exercised in a real session this turn — hooks load next session; logic + wiring are unit-tested. git-commit detection is heuristic."
    },
    {
      "id": "EV-023",
      "type": "validation",
      "summary": "Verified REQ-049 (v0.5.75): 439 unit tests pass incl. new UseTheSkillsTests asserting 'instructions, not FYI' + 'compaction' + 'source of truth' appear in AGENTS.md and CLAUDE.md (hub + skeleton). gap audit (0.5.75), state consistency, prd_gate clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 439,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-049",
        "TRK-041",
        "CHG-027"
      ],
      "limitations": "Advisory; firm wording at the always-read layer raises compliance but cannot force skill invocation. The commit gate (0.5.74) is the hard complement."
    },
    {
      "id": "EV-024",
      "type": "validation",
      "summary": "Verified REQ-050 (v0.5.76): 442 unit tests pass incl. new tests (claude install writes enabledPlugins['prd-plugin@prd-plugin']=true + extraKnownMarketplaces github markusuk1/prd-plugin and preserves hooks; non-claude install writes neither; config merges into a pre-existing settings.json preserving its keys). enabledPlugins/extraKnownMarketplaces shapes grounded against the official claude-code-settings JSON schema. gap audit (0.5.76), state consistency, prd_gate clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 442,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-050",
        "TRK-042",
        "CHG-028"
      ],
      "limitations": "Claude Code mechanism; Claude Desktop should honor the shared .claude/ config but unverified on the desktop UI. Does not resolve dual-delivery (a repo may have both plugin skills and project .claude/skills copies) — that's the per-provider delivery redesign."
    },
    {
      "id": "EV-025",
      "type": "validation",
      "summary": "Verified REQ-051 (v0.5.77): 444 unit tests pass incl. updated plugin-primary tests (no project .claude/skills on --claude; plugin config present; codex/opencode skills still install), --claude-skills escape hatch (function + CLI paths), and a CLI regression test for the main() option-building bug. CLI smoke tests confirm: --claude => no .claude/skills + enabledPlugins set; --claude --claude-skills => .claude/skills/project-memory present. gap audit (0.5.77), state consistency, prd_gate clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 444,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_install.py <tmp> --claude --no-codex --no-opencode",
          "outcome": "ok"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-051",
        "TRK-043",
        "CHG-029"
      ],
      "limitations": "INSTALL-MATRIX/README not yet updated for plugin-primary (Phase 3). Desktop end-to-end (trust -> install -> prd-plugin:* appear) not verified on a live desktop (Phase 4). codex/opencode skeleton cruft (all-host dirs still copied) remains (Phase 1)."
    },
    {
      "id": "EV-026",
      "type": "validation",
      "summary": "Verified REQ-052 (v0.5.78): 450 python tests pass including the new Node unit suite (15 tests via node --test: timestamp injection impossible, next_id race-safe across 8 concurrent processes with no counter lag, foreign 4-space-indent writes leave original lines byte-identical, schema rejections actionable, legacy statuses normalized) and the end-to-end test (fresh temp repo -> prd-install -> real server over stdio JSON-RPC: initialize, tools/list=10, open_goal, file_request, record_evidence with markdown + cross-link, close_goal with EV, prd_validate reports ok, prd_status parity with build_status, gate backstop clean with zero manual JSON edits). Installer merge idempotence + existing-server preservation tested; stop-guard deferred/parked and prd_status legacy-status tests green. gap_audit (0.5.78), state consistency, prd_gate, local_workflow_check clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 450,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "node --test tests/node/server.test.cjs",
          "outcome": "ok",
          "tests_run": 15
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-052",
        "TRK-044",
        "PRD-002",
        "ARCH-002",
        "IMP-002",
        "CHG-030"
      ],
      "limitations": "Phase 3 (.mcpb Claude Desktop packaging) deliberately deferred; packaging rules are recorded in the release notes/REQ. prd_status/prd_validate require a python interpreter (already required by the plugin's hooks); clear ToolError otherwise. Live MCP client adoption (Claude Code session using the tools) not exercised in-suite — covered by the stdio e2e which speaks the same protocol."
    },
    {
      "id": "EV-027",
      "type": "validation",
      "summary": "Hardening loop verified (TRK-045): round 1 (2 parallel auditors + live protocol probes) found 5H/7M/10L incl. lock-ownership races, forged-evidence close, ID burn on malformed state, nested timestamp smuggling, installer clobber of unparseable configs; all fixed with pinned tests. Round 2 (fresh adversarial pass) confirmed every round-1 fix solid and found 1H/3M/6L (brainstorm-slug ID rejection — reproduced against real state, lock wait<stale window — reproduced live at 5028ms, nested-type installer crashes, dry-run disclosure gap); all fixed with pinned tests. Final: 459 python tests pass (Node suite 32), e2e conversation gate-clean, state consistency + prd_gate ok, py_compile + node --check clean, no stray refs.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 459,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "node --test tests/node/server.test.cjs",
          "outcome": "ok",
          "tests_run": 32
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-052",
        "TRK-045",
        "CHG-031"
      ],
      "limitations": "Accepted residuals, documented in code: releaseLock TOCTOU needs a >10s hold plus a ms window; a live holder frozen >10s can be usurped (holds are normally milliseconds); crash between registry write and record write burns one gate-visible ID (inherent to the two-file design)."
    },
    {
      "id": "EV-028",
      "type": "validation",
      "summary": "Verified REQ-053 (v0.5.79): 463 python tests pass incl. new MultiSessionTests written red-first (env opt-out PRD_STOP_GUARD=off/0 and PRD_WORKER_SESSION=1 allow the stop with an open goal; session A becomes owner and stays blocked while session B stops freely; ownership binding pruned when the goal is parked — the 0.5.78 closed-status set honored; decide() stops for non-owner sessions). Legacy state file (flat counters) migrates on read; existing pause/cap/error-fails-open tests green; hub and skeleton hook copies byte-identical (content-equality test). Also verified with npm pack + newline-normalized diff that the published 0.5.78 tarball contains the hardening commit — downstream's missing-commit finding was an LF/CRLF artifact.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 463,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "npm pack prd-plugin@0.5.78 && diff (newline-normalized)",
          "outcome": "identical"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-053",
        "TRK-046",
        "CHG-032"
      ],
      "limitations": "Ownership binds to the first session the guard blocks (not the session that opened the goal — MCP clients don't know their Claude session_id at open time); if the owning session dies, the goal stays open unblocked until closed. Live multi-session conscription not reproduced in-suite; the ownership/opt-out logic is unit- and main()-tested."
    },
    {
      "id": "EV-029",
      "type": "validation",
      "summary": "Verified REQ-055/056/057 (v0.5.80). REQ-055: GRAPH_LANG's exact repro now produces zero incomplete chains; the hub graph reports 0 orphans / 0 incomplete / 20 dangling; the new CanonicalTemplateShapeTests loads templates/implementation-plan.json itself and asserts every task link field appears in FIELD_REL, so the class of bug (hand-rolled fixture that never exercised the shipped field names) cannot recur. REQ-057: the new prd_gate check was run live against the downstream repo D:/Projects/AI-Collab-v3 and produced exactly two findings — REQ-010 (prd_stop_guard.py bug) and REQ-038 (method gap, opens 'PRD Plugin method gap (upstream, for the hub)') — with zero false positives on their ordinary project requests, and it never fires in the hub itself. All 7 mirrors of each edited skill verified byte-identical (unique content hashes: 1).",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 480,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_graph.py --repo-root . validate",
          "outcome": "0 orphans / 0 incomplete chains"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root D:/Projects/AI-Collab-v3",
          "outcome": "2 unsubmitted_plugin_request warnings (REQ-010, REQ-038)"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-055",
        "REQ-056",
        "REQ-057",
        "TRK-047",
        "CHG-033"
      ],
      "limitations": "unsubmitted_plugin_request matches on request text, so a request that discusses a plugin surface only obliquely (no script/skill/hook name and no 'PRD Plugin' phrase) will not be flagged; it is warning severity and never blocks a commit.",
      "created_at": "2026-07-10"
    },
    {
      "id": "EV-030",
      "type": "validation",
      "summary": "Verified REQ-058 (v0.5.81). 506 python tests pass, including 24 new tests written red-first for request_autosubmit (classification, hub-repo and already-submitted no-ops, export, idempotence, delivery from env and from config with env winning, refusal to write into a path that is not a hub, minimal-diff preservation of CRLF/LF/4-space indent/BOM, and fail-open on missing request, unreadable state, and undeliverable hub) and two MCP end-to-end tests that ran (not skipped): filing a plugin bug through the installed server produces the outbox package with no agent action, while an ordinary project bug produces none; and deleting request_autosubmit.py from the install still lets a filing succeed. A classifier-identity test asserts request_autosubmit.PLUGIN_SURFACE_RE is prd_gate.PLUGIN_SURFACE_RE, so the two can never diverge. Live proof: run against a temp copy of AI-Collab-v3's real 38 requests (their repo untouched), the pipeline submitted exactly REQ-010 and REQ-038, skipped REQ-001 as already_submitted, and left all 35 ordinary project requests alone.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 506,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python -m unittest tests.test_mcp_server -v",
          "outcome": "4 tests ran, 0 skipped, OK"
        },
        {
          "command": "autosubmit over a copy of AI-Collab-v3 requests.json (38 records)",
          "outcome": "submitted REQ-010, REQ-038; 35 not_plugin_surface; 1 already_submitted"
        },
        {
          "command": "node --check mcp/server.cjs",
          "outcome": "ok"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-058",
        "TRK-048",
        "CHG-034"
      ],
      "limitations": "Delivery requires a hub checkout on the same filesystem; there is no network transport. Classification is textual, so a request that discusses a plugin surface without naming a script, skill, hook, or the product name is neither auto-submitted nor warned about. The submission writes into the hub inbox only when the operator configured the path; unconfigured repos still park packages in the outbox.",
      "created_at": "2026-07-10"
    },
    {
      "id": "EV-031",
      "type": "validation",
      "summary": "Verified REQ-059/DEC-001 (v0.5.82). 508 python tests pass, including new red-first assertions: the decision-policy skill states shipping is governed by the tier with autonomous as 'standing consent' gated on a green build, while 'secret', 'force-push', and 'another repository' remain in the hard-floor set; and CLAUDE.md/AGENTS.md (hub + skeleton) no longer carry the absolute 'never push, merge to main, force-push, publish ... in any tier' phrasing but do still name secrets and force-push as always-stop. All 7 mirrors of project-decision-policy and project-git-workflow byte-identical (unique hashes 1). gap_audit, release_check, state_consistency, prd_gate clean.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 508,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-059",
        "DEC-001",
        "TRK-049",
        "CHG-035"
      ],
      "limitations": "The change is to method text (skills + always-in-force docs), not an enforced code gate — an agent that ignores the tier is not blocked by a hook from over- or under-asking; prd_gate does not (yet) verify tier-appropriate shipping. autonomous shipping relies on the full gate being run and green, which the skill states as a precondition but does not mechanically enforce at publish time.",
      "created_at": "2026-07-10"
    },
    {
      "id": "EV-032",
      "type": "validation",
      "summary": "Verified REQ-060 (v0.5.83). 522 python tests pass, including 14 new project-llm-wiki tests (skill present with ingest/query/lint; MIT attribution + LICENSE; reference templates present and mirrored; byte-identical across all 7 host mirrors; registered in install-scope + required_skills + INSTALL-MATRIX; knowledge.llm_wiki.enabled default true; and the automatic wiring — session-start nudge, session-close, verification, self-service, and decision-policy router all reference the wiki). Caught and fixed a real regression: the blanket skill-mirror clobbered project-verification-before-completion's downstream-adapted skeleton variant (which strips hub-only scripts gap_audit/release_check/local_workflow_check and adds the 'do not run ... hub-only' guard); restored the adapted skeleton copies from main and re-applied only the wiki bullet. Live install (--codex --opencode --claude --claude-skills) confirmed the skill lands downstream complete with its four reference templates and LICENSE across .agents/.opencode/.claude.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 522,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_install.py <tmp> --codex --opencode --claude --claude-skills --force",
          "outcome": "project-llm-wiki + references + LICENSE present in all three host skill dirs"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-060",
        "TRK-050",
        "CHG-036"
      ],
      "limitations": "The wiki's ingest/query/lint are model-executed per the skill, not enforced by a script or hook — an agent that ignores the session-close ingest step is not blocked. Automatic ingest depends on the agent honoring the nudge and the close steps. The config knowledge block ships via templates (unit-verified); the live-install config assertion was skipped because the smoke test used --force --yes which resets state.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-033",
      "type": "validation",
      "summary": "Verified REQ-061 (v0.5.84). 537 python tests pass, including 15 new backfill tests: backfill_pending true only with marker and no wiki; the surveyor inventories code/docs/state and excludes node_modules/.git/.prd_plugin noise, is read-only (file set unchanged after build_plan), and its CLI emits status + JSON plan; the installer writes the marker for an established repo but not for an empty scaffold, an existing wiki, or a disabled wiki; the nudge and skill carry the backfill wiring. Live end-to-end: prd-install into a temp established repo (real src + doc + git history) wrote the marker, prd_wiki_backfill --status reported pending, and --plan produced proposed topics from the code modules, docs, and state.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 537,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "prd-install into a temp established repo, then prd_wiki_backfill --status/--plan",
          "outcome": "marker written; pending; plan lists src module + docs + topics"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-061",
        "TRK-051",
        "CHG-037",
        "REQ-060"
      ],
      "limitations": "The backfill compile itself is model-executed per the skill, not scripted — the surveyor only produces a grounded plan; an agent that ignores the marker is not blocked from stopping (the marker/nudge/status surface it, they do not enforce it). The proposed-topics inventory includes plugin-installed docs (AGENTS.md/CLAUDE.md/docs/INSTALL-MATRIX.md) as candidate sources; the agent judges relevance. The marker lives in per-clone .prd_plugin/local/, so each clone of an established repo is flagged independently until its wiki exists.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-034",
      "type": "validation",
      "summary": "Dogfooded project-llm-wiki on the hub (TRK-052): created wiki/ + raw/ and deeply backfilled 15 grounded articles across 11 topics (method, decisions, skills, state, mcp, hooks, delivery, requests, knowledge, release, operations) plus one raw as-built source. Seeded by prd_wiki_backfill.py --plan. Lint clean: 66 internal links resolve, every article is in the index, raw refs resolve. Facts grounded against the repo (29 canonical skills, 10 MCP tools, 5 Claude hooks, 8 method docs, the ID prefix registry, the release marker set).",
      "commands": [
        {
          "command": "python scripts/prd_wiki_backfill.py --repo-root . --plan",
          "outcome": "topic inventory produced"
        },
        {
          "command": "wiki lint (links/index/raw refs)",
          "outcome": "15 articles, 0 broken links, 0 missing from index"
        }
      ],
      "linked_ids": [
        "TRK-052",
        "REQ-060",
        "REQ-061"
      ],
      "limitations": "Articles are a first backfill pass compiled largely from this session's grounded knowledge of the repo; some claims (e.g. exact ~21 marker count) are approximate and should be refined on the next ingest. The surveyor counted request-report/ generated artifacts as knowledge (separate fix flagged).",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-035",
      "type": "validation",
      "summary": "Verified REQ-062 (v0.5.85). Reproduced from source: U+26A0 is not in cp1252 (raises charmap UnicodeEncodeError). 539 python tests pass, incl. 2 new: a source scan of scripts/*.py + Claude hooks (hub + skeleton) asserts zero cp1252-unencodable chars, and format_markdown of a backfill-pending status is cp1252-encodable. Live repro: PYTHONIOENCODING=cp1252 python scripts/prd_status.py on a repo with .prd_plugin/local/wiki-backfill-needed crashed before the fix and now prints the backfill line and exits 0. Both prd_precommit_gate copies fixed (U+2192 -> ->).",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 539,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "PYTHONIOENCODING=cp1252 python scripts/prd_status.py --repo-root <tmp-with-marker>",
          "outcome": "exit 0, prints backfill line (crashed before fix)"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-062",
        "TRK-053",
        "CHG-038"
      ],
      "limitations": "The source scan covers scripts/*.py and the Claude hooks; a downstream repo's own scripts are out of scope. stdout hardening is added to prd_status.main specifically; other CLI tools rely on ASCII output plus the scan test rather than a shared reconfigure.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-036",
      "type": "validation",
      "summary": "Verified REQ-063 (v0.5.86). 540 python tests pass (main's 539 + one new backfill test) plus 12 system tests, including a test asserting build_plan excludes request-report/ (and its nested long-run-drift-calibration tree) and docs/evidence/ while still surveying docs/architecture.md. Live end-to-end: the fixed surveyor run against the real hub repo (which has a gitignored request-report/ of 107 files and a docs/evidence/ tree) produced a plan with request-report, calibration, and docs/evidence all absent; code_modules were the real source dirs (tests, scripts, system_tests, bin, index.js, mcp).",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 540,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_wiki_backfill.py --repo-root D:/Projects/prd-plugin --plan --json",
          "outcome": "request-report / calibration / docs-evidence all absent from plan; code_modules are real source dirs"
        },
        {
          "command": "python -m py_compile scripts/*.py",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-063",
        "TRK-054",
        "CHG-039",
        "REQ-061"
      ],
      "limitations": "Exclusion is by directory name (request-report, matched at any depth) plus a docs/evidence path prefix anchored to the repo root; other generated report trees at non-standard paths, or an evidence/ dir nested elsewhere, are not auto-excluded.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-037",
      "type": "validation",
      "summary": "Verified REQ-064 (v0.5.87). 545 python tests pass, incl. 5 new: article + archive templates carry a `> Commit:` field and are mirrored across all 7 skill copies; the skill instructs `git rev-parse` and records the Commit; prd_wiki_backfill.build_plan emits head_commit (verified against a temp git repo). Dogfood: all 18 hub wiki articles stamped with their compile commit (4bb8434); wiki lint clean (0 broken links, index consistent, 0 articles missing the Commit field).",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 545,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "wiki lint (links/index/commit-field)",
          "outcome": "18 articles, 0 broken, 0 without Commit"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-064",
        "TRK-055",
        "CHG-040"
      ],
      "limitations": "The Commit field is recorded by the model per the skill workflow, not auto-stamped by a hook; an agent that skips it is not blocked. head_commit is 'unknown' outside a git repo. The lint 'behind HEAD' check is heuristic (report-only), not an enforced gate.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-038",
      "type": "validation",
      "summary": "Verified REQ-065 (v0.5.88). Analysis confirmed the monitor's 5-validator set predated prd_gate + its newer checks, prd_self_audit (docs drift), prd_graph (traceability), and staleness_audit. 556 python tests pass, incl. 11 new: DEFAULT_VALIDATORS now covers the four; validator_command builds 'prd_gate check' and 'prd_graph --gaps'; new archetype patterns classify unsubmitted_plugin_request/traceability_gap/stale_item; drift_config exposes on_stop (default off) + on_stop_validators (excludes gap_audit/release_check); stop_check runs when on, is skipped when off, and never raises; the prd_drift_check.py hook exists and is wired to Stop (hub+skeleton); config carries on_stop default off; /prd-drift command exists. Live: all four new validators run and parse through _run_validator on the hub (prd_gate ok, prd_graph ok, prd_self_audit ok, staleness attention); with on_stop enabled the hook surfaced '14 drift finding(s): 13 from prd_self_audit, 1 from staleness_audit' and exited 0; /prd-hooks drift on/off toggles the config.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 556,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python .claude/hooks/prd_drift_check.py (on_stop enabled)",
          "outcome": "surfaced one-line drift summary, exit 0"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-065",
        "TRK-056",
        "CHG-041"
      ],
      "limitations": "On-Stop check is observation-only and opt-in (default off); it does not block. Running the cheap subset every turn adds latency (esp. prd_self_audit) — acceptable because opt-in. The hub itself keeps drift.monitoring.enabled=false (its own choice); the feature was verified by temporarily enabling it. self_audit/graph findings counts are heuristic drift signals, not a gate.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-039",
      "type": "validation",
      "summary": "Verified REQ-066 (v0.5.89). 557 python tests pass. The new test_every_command_is_present_in_all_locations enforces full parity and was proven to catch the gap: temporarily removing prd-drift.md from templates/repo-skeleton/.claude/commands failed it with 'missing commands: [prd-drift.md]'. All three command dirs now hold 9 commands including prd-drift.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 557,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "parity test with prd-drift removed from skeleton",
          "outcome": "FAILED (caught the gap)"
        }
      ],
      "linked_ids": [
        "REQ-066",
        "REQ-065",
        "CHG-042"
      ],
      "limitations": "Parity is checked by filename across the three dirs, not content-identity; a command present everywhere but with divergent bodies would not be flagged by this test.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-040",
      "type": "validation",
      "summary": "Verified REQ-067 (v0.5.90). 562 python tests pass, incl. 5 new: drift_event_from_snapshot is compact (no '\"findings\"'), versioned (schema_version 1.0), and carries plugin_version/drift_score/total_findings/by_validator/archetypes; session_start+end append exactly two events with the right types and version 9.9.9; stop_check appends a stop_check event; read_drift_events honors --limit; the --log CLI emits JSON. Live: a session-start run wrote one events.jsonl line stamped plugin_version 0.5.90, and --log --format markdown rendered it. The Windows-console scan caught a U+2192 in a docstring, now fixed to ASCII.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 562,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "drift_monitor.py --session-start then --log --format markdown",
          "outcome": "one compact event emitted + rendered"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-067",
        "TRK-057",
        "CHG-043"
      ],
      "limitations": "The feed is gitignored per-clone telemetry — it is not committed or exported, so drift history does not travel with the repo (a deliberate call; committing per-turn events would churn git). Consumers must run on the same checkout. plugin_version is null only when neither a host manifest nor config installed_version is present.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-041",
      "type": "validation",
      "summary": "Verified REQ-068 (v0.5.91). 577 python tests pass, incl. 15 new (injected fetcher, no real npm): update_available when npm ahead; no update when current; disabled path makes zero npm calls; TTL cache avoids refetch and expiry refetches; --force refetches; network failure is fail-open; status() is cache-only; set_enabled toggles config; CLI exits 0; nudge/config/command/registration wiring. Live: fetch_latest returned 0.5.90 from real npm; a simulated repo on 0.5.80 surfaced 'update available: 0.5.90 (you're on 0.5.80)' in both the check and /prd-status. Cross-platform npm resolution fixed a Windows FileNotFoundError (npm.cmd). Windows-console scan caught a U+2192 in a docstring, fixed to ASCII.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 577,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "prd_version_check.py --check on a repo at 0.5.80",
          "outcome": "update available: 0.5.90"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-068",
        "TRK-058",
        "CHG-044"
      ],
      "limitations": "Needs npm on PATH and network to learn 'latest'; without them it fails open (no update shown). The nudge reads a cache warmed on a prior Stop, so a brand-new install shows nothing until after the first refresh. Version comparison is loose semver (numeric major.minor.patch; pre-release tags ignored).",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-042",
      "type": "validation",
      "summary": "Verified REQ-069 (v0.5.92). 582 python tests pass, incl. 5 new: export off writes no committed file; export on writes the committed feed (one schema_version-1.0 line, correct type); custom path honored; default path is committed (not under .prd_plugin/local/); prd_hooks drift export on/off toggles config. Live: /prd-drift export on then a session-start run wrote .prd_plugin/drift/events.jsonl (committed) AND the local feed, both with the same event.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 582,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "prd_hooks drift export on + drift_monitor --session-start",
          "outcome": "committed + local feed both written"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-069",
        "TRK-059",
        "CHG-045",
        "REQ-067"
      ],
      "limitations": "Export appends unconditionally when enabled — a long-running repo with on-Stop drift enabled will grow the committed feed each turn; the consumer decides when to commit/rotate it. The committed path is written but not auto-committed; the repo owner commits it.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-043",
      "type": "validation",
      "summary": "Verified REQ-070 (v0.5.93). The configuration registry declares each supported toggle's type, default, controls, and allowed enum values; get/set/list behavior, validation, nested writes, CLI round trips, downstream registration, and BOM-safe source handling were verified.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 597,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "prd_config.py list / set / get",
          "outcome": "registry listed; valid sets written; invalid enum rejected"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-070",
        "TRK-060",
        "CHG-046"
      ],
      "limitations": "The registry is hand-maintained in prd_config.py — a new config toggle must be added to TOGGLES to appear in the contract (a test pins the known set, so an omission for those is caught). The Claude-hooks enable/disable (settings.json) is intentionally not in this config registry.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-044",
      "type": "validation",
      "summary": "Verified REQ-071 Phase 1 (v0.5.94). 604 python tests pass, incl. 7 new parity tests: the shared .prd_plugin/hooks/ scripts are byte-identical to .claude/hooks/ and ship in the skeleton; .codex/hooks.json (hub + skeleton) wires prd_nudge on SessionStart+UserPromptSubmit and stop_guard/session_report/drift_check/archive on Stop; Codex covers the same four behaviors Claude does; the shared hooks are cp1252-safe. Live: a codex install produced .codex/hooks.json with events [SessionStart, UserPromptSubmit, Stop] and the shared hooks under .prd_plugin/hooks/. Host event models grounded via developers.openai.com/codex/hooks (5 events) and opencode.ai/docs/plugins (session.idle, tool.execute.before).",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 604,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "prd-install --codex then inspect .codex/hooks.json",
          "outcome": "nudge on SessionStart/UserPromptSubmit; stop_guard+session_report+drift_check+archive on Stop"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-071",
        "TRK-061",
        "CHG-047"
      ],
      "limitations": "Phase 1 only. precommit_gate (PreToolUse) and log_skill (PostToolUse) are not yet wired for Codex — they parse the event payload (git command / tool name) and use host-specific deny semantics, needing an adapter (Phase 1b). opencode gets no behavioral hooks yet — it needs a JS plugin on session.idle + tool.execute.before (Phase 2). stop_guard's session-ownership binding relies on a session_id from the Stop payload; under Codex it degrades to no-owner (still guards run-until-done, just without multi-session ownership precision).",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-045",
      "type": "validation",
      "summary": "Verified REQ-071 complete (v0.5.95). 610 python tests pass, incl. 13 cross-host parity tests: shared hooks byte-identical + skeleton-shipped + cp1252-safe; Codex wires nudge (SessionStart+UserPromptSubmit), stop_guard/session_report/drift_check/archive (Stop), precommit_gate (PreToolUse), log_skill (PostToolUse) - all five events, hub + skeleton; the opencode plugin exists (hub+skeleton, identical), wires session.idle + tool.execute.before to the right scripts, and documents the run-until-done limitation. Codex PreToolUse payload/deny grounded via learn.chatgpt.com/docs/hooks (tool_name/tool_input.command/cwd + exit-2), opencode API via opencode.ai/docs/plugins (.opencode/plugins/, named async export, $ shell, session.idle/tool.execute.before). Live: a --codex --opencode install produced .codex/hooks.json with all 5 events and .opencode/plugins/prd-hooks.js. node --check passed on the JS.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 610,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "node --check .opencode/plugins/prd-hooks.js",
          "outcome": "valid"
        },
        {
          "command": "prd-install --codex --opencode then inspect",
          "outcome": "codex all 5 events; opencode plugin shipped"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-071",
        "TRK-061",
        "CHG-048"
      ],
      "limitations": "opencode run-until-done cannot be enforced (session.idle is a non-blocking notification) - it degrades to a printed reminder; this is a host capability ceiling, not a plugin gap. The opencode plugin's event handlers are validated structurally (node --check + content/wiring asserts) but not executed against a live opencode runtime in CI. Skill logging (PostToolUse/log_skill) only fires when a host emits a 'Skill' tool event, which is Claude-native; on Codex/opencode it is a harmless no-op.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-046",
      "type": "validation",
      "summary": "Verified REQ-073 (v0.5.96). 611 python tests pass, incl. a new test asserting all four docs (AGENTS.md/CLAUDE.md hub + skeleton) mention 'wiki' and name 'project-llm-wiki'. Confirmed before the fix that none of the four mentioned the wiki and it was in no skill table, while skill-promotion ('use the skills') and workflow-promotion (project-decision-policy) were already present.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 611,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "grep wiki AGENTS.md CLAUDE.md (before)",
          "outcome": "0 mentions; after: promoted in all 4"
        }
      ],
      "linked_ids": [
        "REQ-073",
        "CHG-049",
        "REQ-060"
      ],
      "limitations": "Docs-only change; it promotes the wiki but does not itself enforce querying/ingesting (the nudge, session-close, and verification skills do the behavioral wiring).",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-047",
      "type": "validation",
      "summary": "Verified REQ-074 (v0.5.97). 615 python tests pass, incl. 4 new freshness tests: default ttl_hours <=1 in the templates and the prd_config registry, fetch_latest accepts a timeout, and the nudge calls check() (in-session refresh) not just status(). Live repro of the exact reported case: a simulated repo on installed 0.5.95 with a cold cache ran the nudge and surfaced 'update available: 0.5.96 (you're on 0.5.95)' from the real registry, writing the refreshed cache in the same run. Version-check confirmed independent of drift (separate automation.version_check toggle).",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 615,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "nudge in a 0.5.95 repo, cold cache, real npm",
          "outcome": "surfaced 'update available: 0.5.96' in-session"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-074",
        "CHG-050",
        "REQ-068"
      ],
      "limitations": "Freshness is still bounded by ttl_hours (default now 1h) — a version published within the last check interval won't surface until the interval elapses; set ttl_hours to 0 for a check every session start. The in-session refresh adds up to a 4s npm call on the first prompt after the TTL expires (fail-open, cached the rest of the interval).",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-048",
      "type": "validation",
      "summary": "Verified REQ-075 (v0.5.98). 616 python tests pass, incl. new tests: --force preserves state (tracking.json custom data) AND config.json (custom autonomy_level) while refreshing a stale plugin hook, reporting them under skeleton.preserved; --force alone preserves config.json; --force --yes still resets state; plain install still skips existing files. Live repro of the exact reported scenario: a target with existing state + custom config + a stale .prd_plugin/hooks/prd_nudge.py, run through `prd-install . --codex --force` (no --yes): printed 'preserving your existing state/config', exit 0, tracking.json + config.json content intact, the stale hook refreshed, and other state files seeded. Replaced the old test that asserted --force overwrites config.json (which encoded the bug).",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 616,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "prd-install . --codex --force on a repo with state+config+stale hook",
          "outcome": "state+config preserved, hook refreshed, no abort"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-075",
        "TRK-062",
        "CHG-051"
      ],
      "limitations": "config.json is protected (preserved), so NEW config keys added by later plugin versions do not propagate into an existing config.json — features fall back to their code defaults when a key is absent (readers use .get(key, default)), so this is safe but means new toggles aren't written to the user's file until they set them or --yes. CLAUDE.md/AGENTS.md remain plugin-refreshable by --force (method docs must stay current); a repo that heavily customizes them should keep custom content elsewhere.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-049",
      "type": "validation",
      "summary": "Verified REQ-076 (v0.5.99). 622 python tests pass, incl. 6 new: no-wiki returns ok/no findings; a current article (Commit==HEAD) is not flagged; an unstamped article is flagged; an article advanced >= threshold commits behind HEAD is flagged 'attention'; the --drift CLI emits the validator JSON; and wiki_drift is present in drift_monitor ON_STOP_VALIDATORS + DEFAULT_VALIDATORS + SCRIPT_MAP with a --drift command. Live on the hub: prd_wiki_backfill --drift reported '18 articles: 0 stale, 0 unstamped, 0 missing from index' (status ok), and drift_monitor._run_validator('wiki_drift') returned a well-formed result.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 622,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "prd_wiki_backfill.py --drift on the hub",
          "outcome": "18 articles, 0 stale, status ok"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "ok"
        }
      ],
      "linked_ids": [
        "REQ-076",
        "CHG-052",
        "REQ-064"
      ],
      "limitations": "Staleness is measured as commits-behind-HEAD of the article's Commit stamp (threshold 25), not whether the article's specific cited sources changed — so a busy repo may flag articles that are still accurate. Requires git and the Commit stamps (0.5.87+); pre-0.5.87 articles read as unstamped. Ingest-manual drift is NOT included (no ingest manual in prd-plugin yet).",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-050",
      "type": "validation",
      "summary": "Verified REQ-077 + REQ-078 (v0.6.0). 628 python tests pass, incl. 6 new ingest-manual-drift tests: no-manual returns ok/nothing-to-drift; a manual stamped at HEAD is not flagged; a manual >= threshold commits behind HEAD is flagged 'attention'; an unstamped manual is flagged; the --drift CLI emits validator JSON; the hub's own manual is conformant and current. The manual passes the kit conformance validator. Live on the hub: drift_monitor._run_validator('ingest_manual_drift') returned status ok, summary '1 manual(s): 0 stale, 0 unstamped, 0 non-conformant'; ingest_manual_drift is present in DEFAULT_VALIDATORS + ON_STOP_VALIDATORS + DEFAULT_WEIGHTS + SCRIPT_MAP and the archetype categorizer recognizes its findings.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 628,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python ingest-manual-kit/validate_ingest_manual.py docs/prd-plugin-ingest-manual.html",
          "outcome": "conformant to ingest-manual/v1"
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root .",
          "outcome": "ok (- None)"
        }
      ],
      "linked_ids": [
        "REQ-077",
        "REQ-078",
        "CHG-053",
        "CHG-054",
        "TRK-063"
      ],
      "limitations": "Ingest-manual conformance in the drift check requires the authoring kit vendored at ingest-manual-kit/ (present in the hub); downstream repos without the kit get staleness-only detection. Staleness is commits-behind-HEAD of meta.commit (threshold 25), not source-specific change tracking.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-051",
      "type": "validation",
      "summary": "Verified REQ-079 (v0.6.1). 630 python tests pass, incl. the two decisive new cases: a change to a file the manual CITES is flagged ('cited source changed since stamp'), while 6 unrelated commits that do not touch the cited file are NOT flagged (the win over commit-count) -- plus a commit-count fallback when no citable paths exist, unstamped, no-manual, and CLI JSON. Live on the hub the detector correctly flagged the shipped manual as drifted because the 0.6.0 merge changed cited files (.prd_plugin/config.json +18 more); after refreshing and re-stamping the manual it returns status ok.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 630,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/ingest_manual_drift.py --repo-root . --drift --format json (pre-restamp)",
          "outcome": "attention: 1 drifted (cited source changed) -- .prd_plugin/config.json +18 more"
        },
        {
          "command": "python ingest-manual-kit/validate_ingest_manual.py docs/prd-plugin-ingest-manual.html",
          "outcome": "conformant to ingest-manual/v1"
        }
      ],
      "linked_ids": [
        "REQ-079",
        "CHG-055",
        "TRK-064",
        "REQ-078"
      ],
      "limitations": "Cited-path detection trusts only <code> tokens containing a '/' that resolve to an existing repo file/dir; bare filenames and globs/placeholders are ignored (conservative -- may miss a cited-but-ambiguous source). A release that bumps a cited config/state file (e.g. .prd_plugin/config.json) legitimately marks the manual as drifted until it is re-stamped, which is the intended regenerate signal.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-052",
      "type": "validation",
      "summary": "Verified REQ-080 (v0.6.2). 631 python tests pass, incl. a reproduction test: after prd-install --force on a repo whose config.json carried a stale installed_version (0.0.1) plus a user autonomy_level, config.json.plugin.installed_version is refreshed to the hub version while autonomy_level is preserved, and prd_version_check.installed_version reads the fresh value. Updated two tests that had encoded the buggy full-preservation behavior. Live repro: a temp install with config stamped 0.5.90 read 0.5.90 before --force and 0.6.1 (hub) after.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 631,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "live: install, stale config to 0.5.90, --force, prd_version_check.installed_version",
          "outcome": "0.5.90 before -> 0.6.1 after (fresh)"
        }
      ],
      "linked_ids": [
        "REQ-080",
        "CHG-056",
        "TRK-065",
        "REQ-075"
      ],
      "limitations": "Only the config.json marker is refreshed; the version check still reads config.json as the single source. A repo updated with a pre-0.6.2 installer keeps its stale marker until it is re-installed with 0.6.2+.",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-053",
      "type": "validation",
      "summary": "Verified REQ-081 (v0.6.3). 641 python tests pass, incl. 10 new fork_version_check tests: disabled/no-source/no-marker are no-ops; a newer remote is flagged; up-to-date and older-remote are silent; fetch failure is fail-open; dotted version_field extraction; TTL cache reuse; CLI --drift JSON. Live: the real prd_nudge hook runs clean (exit 0) and is silent about fork when unconfigured; a simulated fork consumer (FORK-VERSION=1, injected latest=4) reports update_available and the nudge would print 'a new fork version is available: 4 (you are on 1)'. drift_monitor._run_validator('fork_drift') returns status ok ('not configured') on the hub and fork_drift is in DEFAULT_VALIDATORS+ON_STOP_VALIDATORS+SCRIPT_MAP with archetype recognition. prd_config lists the 5 new fork toggles.",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 641,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python .claude/hooks/prd_nudge.py (hub, fork disabled)",
          "outcome": "exit 0, no fork line"
        },
        {
          "command": "simulated consumer: fork_version_check.check(root, fetch=lambda:4)",
          "outcome": "update_available True, 1->4"
        }
      ],
      "linked_ids": [
        "REQ-081",
        "CHG-057",
        "TRK-066",
        "REQ-076"
      ],
      "limitations": "Requires the fork side to publish a machine-readable manifest (or expose the field in /v1/status) for repo-pinned consumers; that manifest is the fork owner's to add. The local marker path and version_field are per-repo config. Surfacing on Stop still requires the repo to enable fork.version_check (and, for the drift-monitor path, drift.monitoring.on_stop).",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-054",
      "type": "validation",
      "summary": "Verified REQ-082 (v0.7.0). 652 python tests pass, incl. 11 new prd_tools tests: the UTCP manual is valid (utcp_version/manual_version/tools), every tool is read-only cli-over-this-script with band/cap tags, the manual covers all 7 subcommands, and each tool returns JSON with a text field (status/tracking/decisions/evidence/wiki/drift/gate), incl. cross-repo via --repo-root and clean unknown-tool error. Live on the hub: all 7 tools return real data (status autonomy=autonomous; tracking 25; decisions DEC-001; evidence 25; wiki drift 15/18 stale; gate 0 findings); utcp.json generated from the same source (7 tools). Grounded the schema against @utcp/cli + AI-Collab's own utcp.json (manual_version 1.0.0, utcp_version 1.0.2, cli call templates).",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "ok",
          "tests_run": 652,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "python scripts/prd_tools.py --utcp-manual --format json --output utcp.json",
          "outcome": "7-tool UTCP manual"
        },
        {
          "command": "python scripts/prd_tools.py status|tracking|decisions|evidence|wiki|drift|gate --repo-root .",
          "outcome": "all return JSON with real data"
        }
      ],
      "linked_ids": [
        "REQ-082",
        "CHG-058"
      ],
      "limitations": "prd-plugin ships the tools + manual; a UTCP host still has to mount the manual (via @utcp/cli) and bridge to MCP -- that wiring lives on the AI-Collab hub side. The hub currently hand-defines tracking/decisions; it should switch to mounting prd-plugin's manual (--utcp-manual discovery) to pick up drift/wiki/status/gate. Writes are intentionally not exposed (observe-only).",
      "created_at": "2026-07-11"
    },
    {
      "id": "EV-057",
      "type": "validation",
      "summary": "Verified v0.9.0 minimal CRAFTE state tools after six CHML fix cycles: 40 Node tests and 678 full tests pass; installed-server, concurrency, stale-registry, duplicate, rollback, lifecycle, state, release, gate, self-audit, and seven drift validators are clean.",
      "linked_ids": [
        "REQ-085",
        "TRK-074",
        "TRK-075",
        "IMP-TASK-031",
        "IMP-TASK-032",
        "IMP-TASK-033",
        "HLT-006"
      ],
      "created_at": "2026-07-12",
      "commands": [
        {
          "command": "node --test tests/node/server.test.cjs",
          "outcome": "40 passed"
        },
        {
          "command": "python -m unittest discover -s tests -v",
          "outcome": "678 passed"
        },
        {
          "command": "python scripts/local_workflow_check.py",
          "outcome": "ok"
        },
        {
          "command": "python scripts/prd_self_audit.py --repo-root . --format json",
          "outcome": "0 CHML findings"
        },
        {
          "command": "configured seven-validator on-stop re-audit",
          "outcome": "7 ok; 0 findings"
        }
      ]
    },
    {
      "id": "EV-058",
      "type": "validation",
      "summary": "Verified the tag-triggered npm publication policy, promoted release memory, and MEM-aware state linking after audit/fix/reaudit: 41 Node tests and 681 full tests pass; local workflow, release/gap/state/gate, zero-CHML self-audit, graph, wiki, manual, staleness, and fork validators are clean.",
      "linked_ids": [
        "REQ-086",
        "TRK-076",
        "TRK-077",
        "TRK-078",
        "HLT-007",
        "MEM-001"
      ],
      "created_at": "2026-07-12",
      "commands": [
        {
          "command": "node --test tests/node/server.test.cjs",
          "outcome": "41 passed"
        },
        {
          "command": "python -m unittest discover -s tests -v",
          "outcome": "681 passed"
        },
        {
          "command": "python scripts/local_workflow_check.py",
          "outcome": "ok"
        },
        {
          "command": "python scripts/prd_self_audit.py --repo-root . --format json",
          "outcome": "0 critical/high/medium/low findings"
        },
        {
          "command": "configured seven-validator re-audit",
          "outcome": "all ok; graph has no orphans or incomplete chains"
        }
      ],
      "limitations": "Historical dangling graph references remain the pre-existing accepted inventory; this change introduces no orphan or incomplete chain."
    },
    {
      "id": "EV-059",
      "type": "validation",
      "summary": "Focused validation proves agent-scoped tracking branches isolate worktree writes and promote without duplicate TRK IDs or lost updates.",
      "linked_ids": [
        "REQ-087",
        "TRK-079",
        "TRK-080",
        "DBR-001",
        "HLT-008"
      ],
      "created_at": "2026-07-13",
      "commands": [
        {
          "command": "node --test tests/node/server.test.cjs",
          "outcome": "44/44 passed, including isolated-worktree, idempotency, owner, merge, and conflict cases"
        },
        {
          "command": "python -m unittest tests.test_state_consistency_check tests.test_prd_graph -v",
          "outcome": "28/28 passed, including branch/canonical consistency and graph provenance"
        },
        {
          "command": "python -m unittest tests.test_config_toggles -v",
          "outcome": "20/20 passed; branch defaults and toggles validated across config templates"
        }
      ],
      "limitations": "Focused evidence only; full suite, downstream install parity, audits, and release verification remain pending."
    },
    {
      "id": "EV-060",
      "type": "validation",
      "summary": "Agent-scoped tracking branches verified across isolated worktree simulation, conflict rejection, owner enforcement, malformed-delta rejection, interrupted-write recovery, idempotent promotion, installer delivery, state/graph validation, 689-test full suite, local workflow gate, drift validators, ingest-manual validation, and npm package inspection. The package audit also removed 38 Python cache artifacts from the tarball.",
      "linked_ids": [
        "REQ-087",
        "TRK-079",
        "TRK-081",
        "TRK-082",
        "HLT-008",
        "DBR-001",
        "PRD-002",
        "ARCH-002"
      ],
      "created_at": "2026-07-13",
      "commands": [
        {
          "command": "python -m unittest discover -s tests -v",
          "outcome": "689 tests passed"
        },
        {
          "command": "python scripts/local_workflow_check.py",
          "outcome": "completed with no gate findings"
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root . --format json",
          "outcome": "0 errors, 0 warnings, 0 infos"
        },
        {
          "command": "python scripts/prd_self_audit.py --repo-root . --format json",
          "outcome": "0 findings"
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.9.2",
          "outcome": "no findings"
        },
        {
          "command": "python scripts/release_check.py",
          "outcome": "no findings"
        },
        {
          "command": "npm pack --dry-run --json",
          "outcome": "prd-plugin@0.9.2, 438 entries, 0 cache artifacts"
        }
      ],
      "limitations": "Remote merge, tag-triggered GitHub Actions publication, and npm registry visibility remain pending and are owned by TRK-082."
    },
    {
      "id": "EV-061",
      "type": "validation",
      "summary": "Release 0.9.2 verified end-to-end: main and annotated v0.9.2 were pushed at feffaac; GitHub Actions Publish to npm run 29242622943 completed successfully for the tag; npm registry serves prd-plugin@0.9.2 with tarball shasum b8832dc5dde97ed4b071e252d2ac82e72248e35e.",
      "linked_ids": [
        "REQ-087",
        "TRK-079",
        "TRK-082",
        "DBR-001",
        "EV-060",
        "CHG-063",
        "DEC-004"
      ],
      "created_at": "2026-07-13",
      "commands": [
        {
          "command": "git push origin main && git push origin v0.9.2",
          "outcome": "remote main advanced to feffaac and annotated v0.9.2 was created"
        },
        {
          "command": "GitHub Actions Publish to npm run 29242622943",
          "outcome": "completed successfully for v0.9.2 at feffaac"
        },
        {
          "command": "npm view prd-plugin@0.9.2 version dist.shasum time.0.9.2 --json",
          "outcome": "version 0.9.2 is visible; shasum b8832dc5dde97ed4b071e252d2ac82e72248e35e"
        }
      ],
      "limitations": "No unresolved change-specific limitations."
    },
    {
      "id": "EV-062",
      "type": "validation",
      "summary": "Parallel tracking branch delivery gaps were fixed across runtime enforcement, discovery, validators, skills, templates, documentation, tests, and release metadata; repeated audits are clean.",
      "linked_ids": [
        "REQ-088",
        "HLT-009",
        "TRK-083",
        "TRK-084",
        "TRK-085",
        "PRD-002",
        "ARCH-002",
        "IMP-002"
      ],
      "created_at": "2026-07-13",
      "commands": [
        {
          "command": "python scripts/local_workflow_check.py",
          "outcome": "PASS: 701 tests and local workflow completed"
        },
        {
          "command": "python scripts/prd_self_audit.py --repo-root . --format json",
          "outcome": "PASS: critical 0, high 0, medium 0, low 0, info 0"
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root . --format json",
          "outcome": "PASS: 0 errors, 0 warnings, 0 infos"
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.9.4",
          "outcome": "PASS: no findings"
        },
        {
          "command": "python scripts/release_check.py",
          "outcome": "PASS: no findings for 0.9.4"
        },
        {
          "command": "python scripts/ingest_manual_drift.py --repo-root . --drift --format json",
          "outcome": "PASS: no drift"
        },
        {
          "command": "python scripts/prd_wiki_backfill.py --repo-root . --drift --format json",
          "outcome": "PASS: no drift"
        },
        {
          "command": "npm pack --dry-run --json",
          "outcome": "PASS: prd-plugin 0.9.4 package, 438 entries"
        }
      ],
      "limitations": "Remote publication verification is recorded separately after the tag-triggered workflow completes."
    },
    {
      "id": "EV-063",
      "type": "review",
      "summary": "Post-review verification confirms parallel tracking enforcement, discovery, malformed-DBR isolation, required validation, downstream workflow parity, and release 0.9.4 are clean.",
      "linked_ids": [
        "REQ-088",
        "HLT-009",
        "TRK-083",
        "TRK-084",
        "TRK-085",
        "EV-062",
        "PRD-002",
        "ARCH-002",
        "IMP-002"
      ],
      "created_at": "2026-07-13",
      "commands": [
        {
          "command": "python scripts/local_workflow_check.py",
          "outcome": "PASS: 701 tests; local workflow completed"
        },
        {
          "command": "node --test tests/node/server.test.cjs",
          "outcome": "PASS: 51 of 51 MCP subtests"
        },
        {
          "command": "python scripts/prd_self_audit.py --repo-root . --format json",
          "outcome": "PASS: critical 0, high 0, medium 0, low 0, info 0"
        },
        {
          "command": "prd_validate plus state consistency",
          "outcome": "PASS: 0 errors, 0 warnings, 0 infos"
        },
        {
          "command": "gap, release, wiki, ingest-manual audits",
          "outcome": "PASS: no findings or drift"
        },
        {
          "command": "npm pack --dry-run --json",
          "outcome": "PASS: prd-plugin 0.9.4, 438 entries"
        }
      ],
      "limitations": "Remote GitHub Actions and npm registry verification occur after the annotated tag is pushed."
    },
    {
      "id": "EV-064",
      "type": "validation",
      "summary": "Downstream .gitignore delivery passed focused, full, system, audit, package, structure, wiki, and manual verification.",
      "linked_ids": [
        "REQ-089",
        "TRK-086",
        "HLT-010",
        "CHG-066"
      ],
      "created_at": "2026-07-13",
      "commands": [
        {
          "command": "python -m unittest discover -s tests -v",
          "outcome": "707 tests passed"
        },
        {
          "command": "python -m pytest system_tests -v",
          "outcome": "12 passed, 6 skipped"
        },
        {
          "command": "python scripts/local_workflow_check.py",
          "outcome": "completed successfully"
        },
        {
          "command": "python scripts/prd_self_audit.py --repo-root . --format json",
          "outcome": "critical/high/medium/low all 0"
        },
        {
          "command": "npm pack + install tarball + npm exec prd-install",
          "outcome": "0.9.5 created .gitignore; request-report ignored; tracking branch trackable"
        },
        {
          "command": "git check-ignore --no-index assertions",
          "outcome": "runtime/generated paths ignored; canonical state/config/evidence/drift/Codex environment trackable"
        },
        {
          "command": "state/gap/release/manual/wiki/JSON checks",
          "outcome": "all clean; 98 JSON and 3 JSONL parsed"
        }
      ]
    },
    {
      "id": "EV-065",
      "type": "review",
      "summary": "Self-review of REQ-089 found no critical, important, or minor defects after the preservation, packaging, documentation, and release-surface pass.",
      "linked_ids": [
        "REQ-089",
        "TRK-086",
        "HLT-010",
        "CHG-066",
        "EV-064"
      ],
      "created_at": "2026-07-13",
      "commands": [
        {
          "command": "git diff --check",
          "outcome": "clean"
        },
        {
          "command": "self-review against REQ-089 and CRAFTE",
          "outcome": "bounded implementation; existing content preserved; npm path proven; no unresolved findings"
        },
        {
          "command": "prd_self_audit + prd_gate",
          "outcome": "0 findings / status ok"
        }
      ]
    },
    {
      "id": "EV-066",
      "type": "validation",
      "summary": "Verified configurable Stop reflections end-to-end: bounded one-pass hook behavior, strict duplicate-safe CRUD, cross-host delivery, upgrade preservation, release hygiene, and zero CHML findings.",
      "linked_ids": [
        "REQ-090",
        "TRK-087",
        "TRK-088",
        "TRK-089",
        "TRK-090",
        "HLT-011",
        "PRD-004",
        "ARCH-004",
        "IMP-005",
        "IMP-TASK-037",
        "IMP-TASK-038",
        "IMP-TASK-039",
        "IMP-TASK-040",
        "IMP-TASK-041"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "727 tests passed"
        },
        {
          "command": "node --test tests/node/server.test.cjs",
          "outcome": "54 tests passed, including concurrent RFQ allocation"
        },
        {
          "command": "npm pack + clean npx prd-install package smoke",
          "outcome": "0.10.0 packed with 444 files; clean install exposed 22 MCP tools; first Stop blocked for reflection and second Stop completed"
        },
        {
          "command": "create custom category/question then npx prd-install . --force",
          "outcome": "custom_review and RFQ-006 remained configured and effectively enabled"
        },
        {
          "command": "python scripts/prd_self_audit.py --repo-root . --format json",
          "outcome": "critical 0, high 0, medium 0, low 0"
        },
        {
          "command": "state_consistency + release_check + gap_audit + prd_graph --gaps + prd_gate",
          "outcome": "all green; no incomplete traceability chains"
        },
        {
          "command": "python ingest-manual-kit/validate_ingest_manual.py docs/prd-plugin-ingest-manual.html",
          "outcome": "conformant to ingest-manual/v1"
        }
      ],
      "limitations": "OpenCode was not launched interactively; its adapter was syntax-checked, mirror/parity-tested, and matched to the official plugin client.session.prompt contract. Claude/Codex hook behavior and the shared Python runtime were executed directly."
    },
    {
      "id": "EV-067",
      "type": "validation",
      "summary": "Verified v0.10.0 tag-triggered publication completed successfully and the expected package is visible on npm.",
      "linked_ids": [
        "REQ-090",
        "TRK-087",
        "TRK-090",
        "IMP-005",
        "IMP-TASK-041",
        "EV-066",
        "CHG-067"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "GitHub Actions Publish to npm run 29309818481",
          "outcome": "completed successfully for tag v0.10.0 at commit a9d26e3; run duration 39s; https://github.com/markusuk1/prd-plugin/actions/runs/29309818481"
        },
        {
          "command": "npm view prd-plugin version dist.tarball --json",
          "outcome": "version 0.10.0; https://registry.npmjs.org/prd-plugin/-/prd-plugin-0.10.0.tgz"
        }
      ]
    },
    {
      "id": "EV-068",
      "type": "validation",
      "summary": "Verified the Substrate adapter configuration contract: shipped configs are identical and disabled by default; prd_config exposes and validates the master switch, modes, capabilities, contract version, and source-reference policy.",
      "linked_ids": [
        "REQ-091",
        "TRK-091",
        "PRD-REQ-030",
        "PRD-ACC-037",
        "PRD-ACC-038",
        "IMP-TASK-042",
        "IMP-VAL-039"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "python -m unittest tests.test_substrate_adapter.ConfigContractTests tests.test_config_toggles -v",
          "outcome": "23 tests passed"
        }
      ],
      "limitations": "This increment covers PRD configuration only; handshake, projection, mutation, reporting, and AI-Collab runtime tasks remain open."
    },
    {
      "id": "EV-069",
      "type": "validation",
      "summary": "Verified the PRD-side Substrate adapter contract: master precedence, deterministic versioned handshake, complete bounded canonical snapshots, local/private exclusions, repo-qualified graph edges, disabled inert behavior, UTCP discovery, and downstream script classification.",
      "linked_ids": [
        "REQ-091",
        "TRK-091",
        "PRD-REQ-031",
        "PRD-REQ-032",
        "PRD-REQ-033",
        "PRD-ACC-039",
        "PRD-ACC-040",
        "PRD-ACC-042",
        "IMP-TASK-043",
        "IMP-TASK-044",
        "IMP-VAL-040",
        "IMP-VAL-041"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "python -m unittest tests.test_script_install_scope_policy tests.test_substrate_adapter tests.test_prd_tools -v",
          "outcome": "35 tests passed"
        },
        {
          "command": "python scripts/prd_substrate.py handshake --repo-root . --format json",
          "outcome": "versioned disabled handshake emitted with no runtime binding or credential fields"
        }
      ],
      "limitations": "This verifies the PRD producer contract only; AI-Collab projection, MCP command routing, delegated execution, and worker correlation remain open."
    },
    {
      "id": "EV-070",
      "type": "validation",
      "summary": "AI-Collab Substrate adapter runtime passed focused, full, Rust, binding, MCP transport, and zero-CHML doctor verification at commit dfdd4a6.",
      "linked_ids": [
        "REQ-091",
        "IMP-006",
        "IMP-VAL-042",
        "IMP-VAL-043",
        "IMP-VAL-044",
        "HLT-012"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "node --test focused PRD adapter and repo-index suites",
          "outcome": "37 passed, 0 failed"
        },
        {
          "command": "npm run verify:local",
          "outcome": "232 tests: 223 passed, 9 skipped, 0 failed; web typecheck passed"
        },
        {
          "command": "cargo check and npm run build -w @ai-collab/spacetime-bindings",
          "outcome": "passed"
        },
        {
          "command": "npm run doctor",
          "outcome": "critical 0, high 0, medium 0, low 0"
        }
      ],
      "limitations": "AI-Collab package publication is outside this evidence; this proves the isolated implementation branch."
    },
    {
      "id": "EV-071",
      "type": "validation",
      "summary": "PRD Plugin 0.11.0 adapter contract, delivery surfaces, installer, package contents, state, release metadata, and documentation passed the complete local gate.",
      "linked_ids": [
        "REQ-091",
        "IMP-006",
        "IMP-VAL-045",
        "HLT-012"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "python scripts/local_workflow_check.py --target-version 0.11.0",
          "outcome": "739 tests passed; local workflow completed"
        },
        {
          "command": "npm pack --dry-run --json",
          "outcome": "0 Python cache artifacts in package"
        },
        {
          "command": "python ingest-manual-kit/validate_ingest_manual.py docs/prd-plugin-ingest-manual.html",
          "outcome": "conformant"
        }
      ]
    },
    {
      "id": "EV-072",
      "type": "review",
      "summary": "Audit-fix-reaudit loop closed all Substrate adapter Critical, High, Medium, and Low findings across PRD Plugin and AI-Collab.",
      "linked_ids": [
        "REQ-091",
        "HLT-012",
        "IMP-006",
        "IMP-VAL-046"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "python scripts/prd_self_audit.py --repo-root . --format json",
          "outcome": "critical 0, high 0, medium 0, low 0"
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.11.0",
          "outcome": "no findings"
        },
        {
          "command": "python scripts/release_check.py and state_consistency_check.py",
          "outcome": "no findings"
        },
        {
          "command": "AI-Collab npm run doctor",
          "outcome": "critical 0, high 0, medium 0, low 0"
        }
      ],
      "limitations": "Historical request-triage/privacy warnings reported by prd_doctor predate REQ-091 and are not adapter CHML findings."
    },
    {
      "id": "EV-073",
      "type": "validation",
      "summary": "Published and integrated the corrected PRD Plugin Substrate adapter contract: npm 0.11.1 is live, GitHub Actions release run 29314627316 succeeded, AI-Collab consumes the published package and passes its full verification and zero-CHML doctor audit, and both remote branches contain the verified commits.",
      "linked_ids": [
        "REQ-091",
        "IMP-006",
        "HLT-012",
        "DEC-005"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "python scripts/local_workflow_check.py --target-version 0.11.1",
          "outcome": "741 tests passed; release, gap, state, and package gates passed"
        },
        {
          "command": "npm pack --dry-run --json",
          "outcome": "0.11.1 package contained 436 entries and zero local, transport, mailbox, or Python-cache leaks"
        },
        {
          "command": "GitHub Actions Publish to npm run 29314627316",
          "outcome": "completed successfully for tag v0.11.1 and commit 4d19290"
        },
        {
          "command": "npm view prd-plugin version",
          "outcome": "0.11.1"
        },
        {
          "command": "AI-Collab npm run verify:local",
          "outcome": "245 tests: 236 passed, 9 intentional skips, 0 failed; web typecheck passed"
        },
        {
          "command": "AI-Collab npm run doctor",
          "outcome": "critical 0, high 0, medium 0, low 0"
        },
        {
          "command": "git push ai-collab HEAD:codex/req-091-substrate-adapter-v3",
          "outcome": "remote feature branch created at commit 648cf1f"
        }
      ],
      "limitations": "The matching AI-Collab GitHub repository has an unrelated default-branch history and the local repository had no configured remote; the verified implementation was therefore pushed safely as a new non-force feature branch rather than overwriting or merging that history."
    },
    {
      "id": "EV-074",
      "type": "validation",
      "summary": "Binary evidence fix verified from regression reproduction through published npm 0.11.2",
      "linked_ids": [
        "REQ-092",
        "TRK-092",
        "HLT-013"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "python -m unittest discover -s tests -q",
          "outcome": "745 tests passed"
        },
        {
          "command": "python scripts/local_workflow_check.py --target-version 0.11.2",
          "outcome": "completed successfully"
        },
        {
          "command": "python scripts/prd_self_audit.py --repo-root . --format json",
          "outcome": "0 CHML findings"
        },
        {
          "command": "npm pack --dry-run --json",
          "outcome": "0.11.2 package includes state_consistency_check.py with 0 local/report/secret-pattern leaks"
        },
        {
          "command": "GitHub Actions Publish to npm run 29322215359",
          "outcome": "run 76 completed successfully for v0.11.2 at commit 5b4fcb3"
        },
        {
          "command": "npm view prd-plugin version --json",
          "outcome": "0.11.2"
        }
      ]
    },
    {
      "id": "EV-075",
      "type": "validation",
      "summary": "Fresh 0.11.2 reproduction isolates local-request autosubmit to the .prd_plugin path classifier",
      "linked_ids": [
        "REQ-093"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "fresh downstream install plus prd_file_request with scope local and affected area .prd_plugin/state/artifacts/prd/PRD-001.json",
          "outcome": "record rewritten to upstream_submission, upstream_submission true, and outbox package created"
        },
        {
          "command": "compare installed 0.6.3 and hub 0.11.2 PLUGIN_SURFACE_RE matches",
          "outcome": "both match prd_plugin inside three canonical artifact paths"
        },
        {
          "command": "message_check and prd_gate against visual-context-engine",
          "outcome": "one stranded outbox package plus a false unsubmitted_plugin_request warning"
        }
      ],
      "limitations": "Diagnosis only. No production fix was implemented and no visual-context-engine project files were edited."
    },
    {
      "id": "EV-076",
      "type": "validation",
      "summary": "Local request routing fix passed regression, full workflow, CHML, gate, package, and self-review checks",
      "linked_ids": [
        "REQ-093",
        "TRK-093",
        "HLT-014"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "python -m unittest discover -s tests -q",
          "outcome": "748 tests passed"
        },
        {
          "command": "python scripts/local_workflow_check.py --target-version 0.11.3",
          "outcome": "completed successfully"
        },
        {
          "command": "python scripts/prd_self_audit.py --repo-root . --format json",
          "outcome": "0 CHML findings"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root . --format json",
          "outcome": "0 errors, 0 warnings"
        },
        {
          "command": "npm pack --dry-run --json",
          "outcome": "prd-plugin@0.11.3 package built successfully"
        },
        {
          "command": "self-review c7ad9fe..4c382fb against REQ-093",
          "outcome": "0 critical, 0 important, 0 minor findings"
        }
      ],
      "limitations": "Remote GitHub Actions publication and npm registry visibility are verified separately after the tag push."
    },
    {
      "id": "EV-077",
      "type": "validation",
      "summary": "Impact-scoped verification core and downstream delivery passed 134 focused neighbour tests after RED/GREEN implementation.",
      "linked_ids": [
        "REQ-094",
        "TRK-094",
        "TRK-095",
        "TRK-096",
        "IMP-TASK-050",
        "IMP-TASK-051",
        "IMP-VAL-047",
        "IMP-VAL-048"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "python -m unittest tests.test_test_scope tests.test_config_toggles tests.test_substrate_adapter tests.test_prd_install tests.test_script_install_scope_policy tests.test_superpowers_adapted_skills -q",
          "outcome": "134 tests passed"
        }
      ],
      "limitations": "This is change-scoped verification. The release-wide gate, package check, code review, and CHML reaudit remain pending."
    },
    {
      "id": "EV-078",
      "type": "review",
      "summary": "Impact-scoped verification contract hardening passed 135 focused tests.",
      "linked_ids": [
        "REQ-094",
        "TRK-094",
        "HLT-015"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "python -m unittest tests.test_test_scope tests.test_config_toggles tests.test_substrate_adapter tests.test_prd_install tests.test_script_install_scope_policy tests.test_superpowers_adapted_skills -q",
          "outcome": "135 tests passed"
        }
      ],
      "limitations": "Release-wide verification and publication checks remain pending."
    },
    {
      "id": "EV-079",
      "type": "validation",
      "summary": "Version 0.13.0 is release-ready with focused and full verification plus zero-finding CHML audits.",
      "linked_ids": [
        "REQ-094",
        "TRK-094",
        "HLT-015",
        "IMP-TASK-052",
        "IMP-VAL-049"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "python -m unittest discover -s tests -q",
          "outcome": "741 tests passed"
        },
        {
          "command": "python scripts/local_workflow_check.py --repo-root . --target-version 0.13.0 --skip-tests",
          "outcome": "all non-test workflow checks passed; tests intentionally not duplicated"
        },
        {
          "command": "python scripts/prd_self_audit.py --repo-root . --format json",
          "outcome": "0 critical, 0 high, 0 medium, 0 low findings"
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root . --format json",
          "outcome": "0 errors, 0 warnings, 0 infos"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root . --format json",
          "outcome": "status ok; 0 errors, 0 warnings"
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.13.0",
          "outcome": "no findings"
        },
        {
          "command": "python scripts/release_check.py --base-ref v0.12.0",
          "outcome": "no findings"
        },
        {
          "command": "npm pack --dry-run --json",
          "outcome": "prd-plugin@0.13.0 package built; 434 entries"
        }
      ],
      "limitations": "Remote tag workflow and npm registry visibility are verified after this release commit is pushed."
    },
    {
      "id": "EV-080",
      "type": "validation",
      "summary": "The v0.13.0 tag resolves to release commit d8c594a and npm reports prd-plugin@0.13.0.",
      "linked_ids": [
        "REQ-094",
        "TRK-094",
        "IMP-TASK-052",
        "CHG-070"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "git rev-list -n 1 v0.13.0",
          "outcome": "d8c594ae18b89593dc5652ad0d3b5b3ebf65e59f"
        },
        {
          "command": "npm view prd-plugin version --json",
          "outcome": "0.13.0"
        }
      ],
      "limitations": "None."
    },
    {
      "id": "EV-081",
      "type": "review",
      "summary": "Unified configuration inventory and planning chain are grounded and gate-clean.",
      "linked_ids": [
        "REQ-095",
        "TRK-097",
        "TRK-098",
        "PRD-007",
        "ARCH-007",
        "IMP-008"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "configuration leaf inventory",
          "outcome": "141 shipped config leaves; 45 registered; 96 currently uncovered by the tool"
        },
        {
          "command": "python -m unittest selected config/hook/install modules",
          "outcome": "141 relevant baseline tests passed"
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root . --format json",
          "outcome": "0 errors, 0 warnings, 0 infos"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root . --format json",
          "outcome": "status ok; 0 errors, 0 warnings"
        }
      ],
      "limitations": "Implementation and the complete catalog classification remain pending."
    },
    {
      "id": "EV-082",
      "type": "validation",
      "summary": "Unified configuration 0.14.0 release verification passed after audit/fix/re-audit: 769 tests; local workflow, state consistency, integrated PRD gate, gap audit, release hygiene, config audit, package dry-run, and diff checks all clean.",
      "linked_ids": [
        "REQ-095",
        "TRK-097",
        "TRK-098",
        "TRK-099",
        "TRK-100",
        "PRD-007",
        "ARCH-007",
        "IMP-008"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "py -3.14 -m unittest discover -s tests -q",
          "outcome": "769 tests passed"
        },
        {
          "command": "py -3.14 scripts/local_workflow_check.py --repo-root . --target-version 0.14.0 --skip-tests",
          "outcome": "completed with no findings"
        },
        {
          "command": "py -3.14 scripts/state_consistency_check.py --repo-root . --format json",
          "outcome": "0 errors, 0 warnings, 0 infos"
        },
        {
          "command": "py -3.14 scripts/prd_gate.py check --repo-root . --format json",
          "outcome": "0 errors, 0 warnings"
        },
        {
          "command": "py -3.14 scripts/gap_audit.py --target-version 0.14.0",
          "outcome": "no findings"
        },
        {
          "command": "py -3.14 scripts/release_check.py",
          "outcome": "no findings across 81 changed files"
        },
        {
          "command": "npm pack --dry-run --json",
          "outcome": "prd-plugin@0.14.0, 439 files"
        },
        {
          "command": "py -3.14 scripts/prd_config.py audit --json",
          "outcome": "155 settings; 0 unclassified, unknown, invalid, or missing"
        }
      ],
      "limitations": "Publication verification is recorded separately after the tag-triggered GitHub workflow and npm registry update."
    },
    {
      "id": "EV-083",
      "type": "validation",
      "summary": "Release 0.14.0 publication confirmed: annotated tag v0.14.0 was pushed at a63aff6, npm registry serves prd-plugin@0.14.0, and the owner confirmed receipt of the publication email.",
      "linked_ids": [
        "REQ-095",
        "TRK-097",
        "EV-082"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "git push origin v0.14.0",
          "outcome": "annotated tag pushed successfully"
        },
        {
          "command": "npm view prd-plugin@0.14.0 version --json",
          "outcome": "0.14.0"
        },
        {
          "command": "owner confirmation",
          "outcome": "publication email received"
        }
      ],
      "limitations": "Per owner preference, future successful tag pushes are treated as published unless the owner reports otherwise."
    },
    {
      "id": "EV-084",
      "type": "validation",
      "summary": "Deterministic workflow engine release verification completed: WFR-002 passed all nine postconditions; 784 tests passed; CHML was C0/H0/M0/L0; release and gap audits had no findings; npm dry-run produced prd-plugin 0.15.0 with 474 files; final PRD gate had 0 errors and 0 warnings.",
      "linked_ids": [
        "REQ-096",
        "TRK-101",
        "TRK-102",
        "TRK-103",
        "TRK-104",
        "TRK-105",
        "WFR-002"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "python scripts/prd_workflows.py --repo-root . status WFR-002 --json",
          "outcome": "completed, attempt 4, nine completed receipts"
        },
        {
          "command": "python -m unittest discover -s tests -v",
          "outcome": "784 tests passed"
        },
        {
          "command": "python scripts/workflow_chml_audit.py --repo-root . --format json",
          "outcome": "critical 0, high 0, medium 0, low 0"
        },
        {
          "command": "npm pack --dry-run",
          "outcome": "prd-plugin 0.15.0, 474 files"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root . --format json",
          "outcome": "0 errors, 0 warnings"
        }
      ],
      "limitations": "Remote main/tag push and tag-triggered publication are recorded separately after shipping."
    },
    {
      "id": "EV-085",
      "type": "validation",
      "summary": "Remote main push succeeded for the complete PRD Plugin 0.15.0 deterministic workflow implementation at commit 1d8384d.",
      "linked_ids": [
        "REQ-096",
        "TRK-101",
        "TRK-105",
        "CHG-073",
        "EV-084",
        "WFR-002"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "git push origin main",
          "outcome": "fb46dc0..1d8384d main -> main"
        }
      ],
      "limitations": "The annotated v0.15.0 tag is pushed after this canonical closeout commit lands on main."
    },
    {
      "id": "EV-086",
      "type": "validation",
      "summary": "Annotated v0.15.0 tag push succeeded and triggered the repository publication workflow by policy; release is treated as published unless the owner reports otherwise.",
      "linked_ids": [
        "REQ-096",
        "TRK-101",
        "TRK-105",
        "CHG-073",
        "EV-084",
        "EV-085",
        "WFR-002"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "git push origin v0.15.0",
          "outcome": "new tag v0.15.0 -> v0.15.0"
        }
      ],
      "limitations": "Publication status is intentionally not polled; repository policy treats successful tag push as published unless the owner reports failure."
    },
    {
      "id": "EV-087",
      "type": "validation",
      "summary": "PRD Plugin 0.15.1 skill-feature parity repair verified: semantic and workflow CHML are C0/H0/M0/L0; deterministic release run WFR-008 completed all nine steps; 791 tests passed; package dry-run produced prd-plugin-0.15.1.tgz with 476 files; state and final gate passed; the Windows state-lock concurrency test passed ten consecutive 12-thread runs.",
      "linked_ids": [
        "TRK-106"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "python scripts/feature_skill_audit.py --repo-root . --format json",
          "outcome": "status ok; critical/high/medium/low all zero"
        },
        {
          "command": "python scripts/workflow_chml_audit.py --repo-root . --format json",
          "outcome": "status ok; critical/high/medium/low all zero"
        },
        {
          "command": "hub.release WFR-008",
          "outcome": "completed all nine steps; 791 tests passed; release/gap/package/state gates passed; 476 package files"
        },
        {
          "command": "10 x concurrent workflow allocation regression",
          "outcome": "all ten 12-thread runs passed"
        }
      ],
      "limitations": "Release hygiene will be rerun against the committed branch before merge and push."
    },
    {
      "id": "EV-088",
      "type": "validation",
      "summary": "PRD Plugin 0.15.1 was pushed to remote main at 6cc3258 and annotated tag v0.15.1 was pushed successfully, triggering the tag-driven npm publication workflow. Per hub policy the release is treated as published unless the owner reports otherwise.",
      "linked_ids": [
        "TRK-106"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "git push origin main",
          "outcome": "84321bb..6cc3258 main -> main"
        },
        {
          "command": "git push origin v0.15.1",
          "outcome": "new tag v0.15.1 -> v0.15.1"
        }
      ],
      "limitations": "Publication is assumed from the successful tag push by repository policy; no registry polling was performed."
    },
    {
      "id": "EV-089",
      "type": "validation",
      "summary": "Focused 0.15.2 installer verification passed: 118 tests, including exact config-template parity and a fresh installed install.update-check; unified config audit reported 171 classified settings with zero unknown, invalid, missing, or unclassified keys; feature-skill and workflow CHML audits were C0/H0/M0/L0.",
      "linked_ids": [
        "REQ-097",
        "TRK-107"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "focused installer/config/release test set",
          "outcome": "118 tests passed"
        },
        {
          "command": "prd_config audit",
          "outcome": "status ok; all config finding counts zero"
        },
        {
          "command": "feature and workflow CHML audits",
          "outcome": "C0 H0 M0 L0"
        }
      ]
    },
    {
      "id": "EV-090",
      "type": "review",
      "summary": "Code-review audit/fix/reaudit completed: WFR-010 found one minor assertion-precision gap; the fresh-install regression now explicitly requires config.audit unknown=0; the test passed and WFR-011 re-review returned no findings.",
      "linked_ids": [
        "REQ-097",
        "TRK-107",
        "EV-089",
        "CHG-075"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "engineering.code-review WFR-010",
          "outcome": "one minor test-precision finding"
        },
        {
          "command": "fresh installed install.update-check regression",
          "outcome": "passed with unknown=0"
        },
        {
          "command": "engineering.code-review WFR-011",
          "outcome": "zero findings"
        }
      ]
    },
    {
      "id": "EV-091",
      "type": "validation",
      "summary": "PRD Plugin 0.15.2 corrective release verified by deterministic hub.release WFR-012: all nine steps completed; 793 tests passed; config, state, release hygiene, gap audit, package, and final gate passed; workflow CHML was C0/H0/M0/L0; npm pack dry-run produced prd-plugin-0.15.2.tgz with 476 files.",
      "linked_ids": [
        "REQ-097",
        "TRK-107",
        "EV-089",
        "EV-090",
        "CHG-075"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "hub.release WFR-012",
          "outcome": "completed all nine steps"
        },
        {
          "command": "full repository test suite",
          "outcome": "793 tests passed"
        },
        {
          "command": "workflow CHML audit",
          "outcome": "C0 H0 M0 L0"
        },
        {
          "command": "npm pack --dry-run",
          "outcome": "prd-plugin-0.15.2.tgz; 476 files"
        }
      ]
    },
    {
      "id": "EV-092",
      "type": "validation",
      "summary": "PRD Plugin 0.15.2 was pushed to remote main at 8b46623 and annotated tag v0.15.2 was pushed successfully, triggering the tag-driven npm publication workflow. Per hub policy the release is treated as published unless the owner reports otherwise.",
      "linked_ids": [
        "REQ-097",
        "TRK-107",
        "EV-091",
        "CHG-075"
      ],
      "created_at": "2026-07-14",
      "commands": [
        {
          "command": "git push origin main",
          "outcome": "main advanced from 2de833e to 8b46623"
        },
        {
          "command": "git push origin v0.15.2",
          "outcome": "new annotated tag v0.15.2 pushed"
        }
      ]
    },
    {
      "id": "EV-093",
      "type": "validation",
      "summary": "PRD Plugin 0.15.3 safe-update guard verified: non-interactive --force --yes refuses before writes, interactive reset requires the exact phrase, --force preserves protected state/config without recommending --yes, 799 release-boundary tests passed, config and state were clean, workflow CHML was C0/H0/M0/L0, release/gap/package checks passed, and the final gate was clean.",
      "linked_ids": [
        "REQ-054",
        "HLT-002",
        "TRK-108",
        "WFR-015",
        "WFR-016"
      ],
      "created_at": "2026-07-15",
      "commands": [
        {
          "command": "focused installer and close-neighbour verification",
          "outcome": "121 tests passed"
        },
        {
          "command": "engineering.code-review WFR-015",
          "outcome": "completed; two findings corrected"
        },
        {
          "command": "hub.release WFR-016",
          "outcome": "completed; 799 tests and every release gate passed"
        },
        {
          "command": "workflow CHML audit",
          "outcome": "C0 H0 M0 L0"
        },
        {
          "command": "npm pack dry-run",
          "outcome": "prd-plugin-0.15.3.tgz; 476 files"
        }
      ]
    },
    {
      "id": "EV-094",
      "type": "validation",
      "summary": "PRD Plugin 0.15.3 was pushed to remote main at 92ca49c and annotated tag v0.15.3 was pushed successfully, triggering the tag-driven npm publication workflow. Per hub policy the release is treated as published unless the owner reports otherwise.",
      "linked_ids": [
        "REQ-054",
        "TRK-108",
        "EV-093",
        "CHG-076"
      ],
      "created_at": "2026-07-15",
      "commands": [
        {
          "command": "git push origin main",
          "outcome": "main advanced from ed7907f to 92ca49c"
        },
        {
          "command": "git push origin v0.15.3",
          "outcome": "new annotated tag v0.15.3 pushed"
        }
      ]
    },
    {
      "id": "EV-095",
      "type": "validation",
      "summary": "Verified PRD Plugin 0.15.4 knowledge-first self-service and context-lean subagent policy: focused policy regressions passed, semantic feature audit reported C0/H0/M0/L0, wiki drift was clean, and deterministic hub.release WFR-017 completed after 803 tests passed with clean state, config, release, gap, package, and final gate checks.",
      "linked_ids": [
        "TRK-109",
        "DEC-007",
        "WFR-017"
      ],
      "created_at": "2026-07-15",
      "commands": [
        {
          "command": "py -3.14 -m unittest focused policy modules",
          "outcome": "20 focused policy/method tests passed plus 10 tracking/subagent neighbor tests passed"
        },
        {
          "command": "py -3.14 scripts/feature_skill_audit.py --repo-root . --format json",
          "outcome": "critical 0, high 0, medium 0, low 0"
        },
        {
          "command": "py -3.14 scripts/prd_wiki_backfill.py --repo-root . --drift --json",
          "outcome": "23 articles; 0 stale, 0 unstamped, 0 missing"
        },
        {
          "command": "py -3.14 scripts/prd_workflows.py --repo-root . retry WFR-017 --json",
          "outcome": "completed; 803 tests passed; release/gap/package/gate clean"
        }
      ]
    },
    {
      "id": "EV-096",
      "type": "validation",
      "summary": "PRD Plugin 0.15.4 was pushed to remote main at 5cddcd3 and annotated tag v0.15.4 was pushed successfully, triggering the tag-driven npm publication workflow. Per hub policy the release is treated as published unless the owner reports otherwise.",
      "linked_ids": [
        "TRK-109",
        "DEC-007",
        "EV-095",
        "CHG-077"
      ],
      "created_at": "2026-07-15",
      "commands": [
        {
          "command": "git push origin main",
          "outcome": "main advanced from c4c0673 to 5cddcd3"
        },
        {
          "command": "git push origin v0.15.4",
          "outcome": "new annotated tag v0.15.4 pushed"
        }
      ]
    },
    {
      "id": "EV-097",
      "type": "validation",
      "summary": "Verified PRD Plugin 0.15.5 inline wiki-link enforcement and downstream delivery: 32 hub references repaired, focused neighbours passed, semantic CHML reached zero, and the deterministic release workflow completed all gates.",
      "linked_ids": [
        "REQ-098",
        "TRK-110",
        "WFR-020"
      ],
      "created_at": "2026-07-15",
      "commands": [
        {
          "command": "python -m unittest focused wiki/gate/config/install/release modules",
          "outcome": "203 focused Python tests passed"
        },
        {
          "command": "node --test tests/node/server.test.cjs",
          "outcome": "57 MCP tests passed, including workflow receipt identity regression"
        },
        {
          "command": "python scripts/prd_wiki_backfill.py --repo-root . --lint-links --format json",
          "outcome": "0 unlinked Markdown references"
        },
        {
          "command": "python scripts/feature_skill_audit.py --repo-root . --format json",
          "outcome": "critical 0, high 0, medium 0, low 0"
        },
        {
          "command": "python scripts/prd_workflows.py --repo-root . run hub.release",
          "outcome": "WFR-020 completed; 812 tests, release, gap, package, state, config, CHML, and gate checks passed"
        }
      ]
    },
    {
      "id": "EV-098",
      "type": "validation",
      "summary": "Post-review verification confirms configurable wiki-directory support and zero remaining link, state, gate, or CHML findings.",
      "linked_ids": [
        "REQ-098",
        "TRK-110",
        "CHG-078",
        "EV-097",
        "WFR-021"
      ],
      "created_at": "2026-07-15",
      "commands": [
        {
          "command": "focused wiki, gate, config, and skill tests",
          "outcome": "89 passed"
        },
        {
          "command": "engineering.code-review",
          "outcome": "completed with no remaining findings after configured-directory fix"
        },
        {
          "command": "state, gate, CHML, wiki-link, and diff checks",
          "outcome": "all green; CHML 0/0/0/0; unlinked references 0"
        }
      ],
      "limitations": "Full 812-test release verification was already completed by WFR-020 before the final narrow configured-directory fix; that fix was covered by the current focused suite."
    },
    {
      "id": "EV-099",
      "type": "validation",
      "summary": "PRD Plugin 0.15.5 was pushed to main and published through the v0.15.5 release tag.",
      "linked_ids": [
        "REQ-098",
        "TRK-110",
        "CHG-078",
        "EV-097",
        "EV-098",
        "WFR-020",
        "WFR-021"
      ],
      "created_at": "2026-07-15",
      "commands": [
        {
          "command": "git push origin main",
          "outcome": "115d729 pushed successfully"
        },
        {
          "command": "git push origin v0.15.5",
          "outcome": "annotated release tag pushed successfully; npm publication trigger fired"
        }
      ],
      "limitations": "Publication is assumed successful after the tag push unless the owner reports otherwise, per hub policy."
    },
    {
      "id": "EV-100",
      "type": "review",
      "summary": "Validated the Substrate parity audit and synchronization plan: all 16 cited sources exist; AI-Collab 1.0.0 at ba0e33e5 exposes 100 UTCP tools; five canonical JSON artifacts parse; 141 new planning IDs have zero duplicates or missing internal references; 50 focused tests and 813 repository tests pass; live state consistency, workflow CHML, and PRD gate are green.",
      "linked_ids": [
        "REQ-099",
        "TRK-111",
        "PRD-009",
        "ARCH-009",
        "IMP-010",
        "DEC-008",
        "CHG-079"
      ],
      "created_at": "2026-07-15",
      "commands": [
        {
          "command": "focused unittest selection",
          "outcome": "50 tests passed"
        },
        {
          "command": "repository unittest discovery via local workflow check",
          "outcome": "813 tests passed"
        },
        {
          "command": "state_consistency_check.py",
          "outcome": "status ok, no findings"
        },
        {
          "command": "workflow_chml_audit.py",
          "outcome": "critical 0, high 0, medium 0, low 0"
        },
        {
          "command": "prd_gate.py check",
          "outcome": "status ok, 0 errors, 0 warnings"
        },
        {
          "command": "planning cross-reference validator",
          "outcome": "141 IDs, 0 duplicates, 0 missing references"
        },
        {
          "command": "audit source inventory",
          "outcome": "16 of 16 sources exist; 24 capability groups; 19 findings"
        }
      ],
      "limitations": "The legacy traceability_sync_auto scanner reports the repository-wide baseline of 26 dangling and 502 orphan entries because it does not follow canonical planning-artifact references. The new artifact graph was therefore also validated directly. release_check requests a version bump for plan/state-only changes; no runtime/package implementation or release is part of this branch."
    },
    {
      "id": "EV-101",
      "type": "validation",
      "summary": "Verified the complete PRD Plugin 0.16.0 Substrate runtime and repository service-manifest release candidate: 846 Python tests, 58 MCP/Node tests, release workflow, package/version hygiene, gate, wiki-link lint, service/config/catalog/feature/workflow audits, and CHML all passed.",
      "linked_ids": [
        "REQ-093",
        "REQ-099",
        "REQ-100",
        "TRK-112",
        "HLT-014",
        "HLT-016",
        "HLT-017",
        "HLT-018",
        "HLT-019"
      ],
      "created_at": "2026-07-15",
      "commands": [
        {
          "command": "python scripts/local_workflow_check.py --repo-root . --target-version 0.16.0",
          "outcome": "846 tests passed; structured validation, gap audit, release hygiene, doctor, consistency, reports, and skill install audit passed"
        },
        {
          "command": "node --test tests/node/server.test.cjs",
          "outcome": "58 tests passed"
        },
        {
          "command": "python scripts/prd_substrate_catalog.py --repo-root . audit",
          "outcome": "26 capability groups, 103 runtime tools, 31 intents, CHML 0"
        },
        {
          "command": "python scripts/workflow_chml_audit.py --repo-root . --format json",
          "outcome": "critical/high/medium/low all 0"
        },
        {
          "command": "python scripts/prd_services.py audit --repo-root . --json",
          "outcome": "critical/high/medium/low all 0"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root . --format json",
          "outcome": "0 errors, 0 warnings"
        }
      ],
      "limitations": "Live optional AI-Collab calls remain disabled by default and were validated with mocked protocol/runtime boundaries; publication evidence is recorded after the remote tag push."
    },
    {
      "id": "EV-102",
      "type": "validation",
      "summary": "Pushed PRD Plugin 0.16.0 to main and pushed annotated tag v0.16.0, triggering the repository npm publication workflow. Per hub policy the release is treated as published unless the owner reports otherwise.",
      "linked_ids": [
        "REQ-099",
        "REQ-100",
        "TRK-112",
        "EV-101"
      ],
      "created_at": "2026-07-15",
      "commands": [
        {
          "command": "git push origin main",
          "outcome": "d91a5ff..e151aa8 pushed successfully"
        },
        {
          "command": "git push origin v0.16.0",
          "outcome": "annotated v0.16.0 tag pushed successfully; tag publication workflow triggered"
        }
      ]
    },
    {
      "id": "EV-103",
      "type": "validation",
      "summary": "Verified PRD Plugin 0.16.1 request allocator fix and release candidate with canonical duplicate preservation and CHML zero.",
      "linked_ids": [
        "REQ-101",
        "TRK-113",
        "CHG-083"
      ],
      "created_at": "2026-07-15",
      "commands": [
        {
          "command": "node --test --test-name-pattern upstream submission snapshots tests/node/server.test.cjs",
          "outcome": "Regression was red before the fix and passed after it."
        },
        {
          "command": "node --test tests/node/server.test.cjs",
          "outcome": "59 tests passed after version synchronization."
        },
        {
          "command": "python scripts/local_workflow_check.py --repo-root . --target-version 0.16.1",
          "outcome": "846 tests passed and the complete local release workflow completed."
        },
        {
          "command": "python scripts/workflow_chml_audit.py --repo-root . --format json",
          "outcome": "critical 0, high 0, medium 0, low 0."
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root . --format json",
          "outcome": "errors 0, warnings 0."
        },
        {
          "command": "python scripts/prd_wiki_backfill.py --repo-root . --lint-links --format json",
          "outcome": "unlinked 0."
        }
      ],
      "limitations": "The four downstream npm dependency advisories were left unchanged because automatic remediation requires breaking upgrades and is outside this allocator patch."
    },
    {
      "id": "EV-104",
      "type": "validation",
      "summary": "Published PRD Plugin 0.16.1 through the remote version tag after the allocator fix passed release verification.",
      "linked_ids": [
        "REQ-101",
        "TRK-113",
        "CHG-083",
        "EV-103"
      ],
      "created_at": "2026-07-15",
      "commands": [
        {
          "command": "git push origin main",
          "outcome": "main advanced to commit 1505d2f."
        },
        {
          "command": "git push origin v0.16.1",
          "outcome": "annotated v0.16.1 tag pushed successfully; npm publication workflow triggered."
        }
      ],
      "limitations": "Publication is assumed successful after tag push unless the owner reports otherwise. Four downstream npm advisories remain because automated fixes require breaking dependency upgrades."
    },
    {
      "id": "EV-105",
      "type": "validation",
      "summary": "Verified fixed upstream hub defaults, null-route safe migration, custom-route preservation, autosubmit behavior, config validity, wiki links, and canonical state.",
      "linked_ids": [
        "TRK-114",
        "DEC-010",
        "CHG-084"
      ],
      "created_at": "2026-07-15",
      "commands": [
        {
          "command": "python -m unittest tests.test_prd_install tests.test_request_autosubmit tests.test_config_toggles tests.test_llm_wiki -q",
          "outcome": "153 tests passed"
        },
        {
          "command": "python scripts/prd_config.py --repo-root . --json audit",
          "outcome": "0 invalid, unknown, or missing settings"
        },
        {
          "command": "python scripts/prd_wiki_backfill.py --lint-links --fix --format json",
          "outcome": "0 issues"
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root .",
          "outcome": "status ok"
        }
      ]
    },
    {
      "id": "EV-106",
      "type": "validation",
      "summary": "REQ-102 and REQ-103 verified. staleness_audit.py is now downstream_runtime/installed-by-default in both script-install-scope manifests so session.stop's staleness.audit action always has its module. The canonical tool-surface catalog (templates/tool-surface.json) is loaded by prd_tools.load_tool_surface_catalog, installed downstream at .prd_plugin/tool-surface.json by prd_install, accounts for every UTCP tool and all 45 MCP tools, and utcp.json was regenerated to exactly match build_manual() (it had drifted: missing the services tool and newer substrate actions).",
      "linked_ids": [
        "REQ-102",
        "REQ-103",
        "TRK-115"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 856 tests in 70.041s -- OK"
        },
        {
          "command": "python -m unittest tests.test_prd_tools tests.test_mcp_server -v",
          "outcome": "24 tests OK: checked-in utcp.json == build_manual(); catalog UTCP set == registered TOOLS; asymmetric capabilities carry transport_rationale; installed .prd_plugin/tool-surface.json MCP set == live tools/list (45)"
        },
        {
          "command": "python -m unittest tests.test_prd_install tests.test_script_install_scope_policy",
          "outcome": "staleness_audit.py installed in default and both-agent installs; session.stop dependency policy test passes"
        }
      ]
    },
    {
      "id": "EV-107",
      "type": "validation",
      "summary": "PRD Plugin 0.16.3 shipped: all five release gates green (local_workflow_check, gap_audit, release_check, state_consistency_check, prd_gate — zero findings at target 0.16.3), branch merged to main (844d132), annotated v0.16.3 tag pushed to origin; the tag push triggers the GitHub Actions npm publication workflow per the release ceremony.",
      "linked_ids": [
        "TRK-115",
        "REQ-102",
        "REQ-103",
        "CHG-085"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python scripts/local_workflow_check.py --target-version 0.16.3",
          "outcome": "completed, no findings"
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.16.3",
          "outcome": "Findings: None"
        },
        {
          "command": "python scripts/release_check.py",
          "outcome": "30 changed files checked, Findings: None"
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root .",
          "outcome": "Findings: None"
        },
        {
          "command": "python scripts/prd_gate.py check --repo-root .",
          "outcome": "Status: ok"
        },
        {
          "command": "git push origin main && git push origin v0.16.3",
          "outcome": "main ff1fb2f..844d132; new tag v0.16.3"
        }
      ]
    },
    {
      "id": "EV-108",
      "type": "validation",
      "summary": "REQ-105 verified: stop-guard cross-host conscription fixed. New OwnerAgentTests reproduce the ai-collab-v3 REQ-090 scenario (goal owned by AGENT-CODEX blocks a claude-host session) and prove the fix: cross-host goals are excluded, same-host and hostless owners keep run-until-done, an unknown host applies no filter, and the guard picks the session's own goal over a newer cross-host goal. The dispatcher exports --host as PRD_HOOK_HOST and restores it; all four guard copies and both dispatcher copies are byte-identical.",
      "linked_ids": [
        "REQ-105",
        "TRK-116"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python -m unittest tests.test_stop_guard tests.test_hook_dispatcher tests.test_cross_host_hook_parity -v",
          "outcome": "51 tests OK (7 new: 6 OwnerAgentTests + 1 dispatcher host-forwarding)"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 863 tests in 123.805s -- OK"
        }
      ]
    },
    {
      "id": "EV-109",
      "type": "validation",
      "summary": "PRD Plugin 0.16.4 shipped: five release gates green at target 0.16.4, branch merged to main (8bb579a), annotated v0.16.4 tag pushed — the tag push triggers the GitHub Actions npm publication workflow. Inbox fully processed: ai-collab-v3 REQ-085/REQ-090 imported as REQ-104 (in_review) / REQ-105 (implemented in this release); three duplicate packages already shipped as REQ-102/REQ-103 removed; message_check reports 0 new inbox packages.",
      "linked_ids": [
        "TRK-116",
        "REQ-104",
        "REQ-105",
        "REQ-106",
        "CHG-086"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python scripts/{local_workflow_check,gap_audit,release_check,state_consistency_check,prd_gate}.py",
          "outcome": "all five gates: Findings none / Status ok at 0.16.4"
        },
        {
          "command": "git push origin main && git push origin v0.16.4",
          "outcome": "main 12f490e..8bb579a; new tag v0.16.4"
        },
        {
          "command": "python scripts/message_check.py --config .prd_plugin/config.json",
          "outcome": "7 inbox packages, all imported; 0 new; 0 outbox"
        }
      ]
    },
    {
      "id": "EV-110",
      "type": "validation",
      "summary": "Registry planning-counter drift repaired and permanently guarded. Audit found every planning prefix counter (PRD-REQ 73 vs used max 84, IMP-TASK 89 vs 96, ARCH-DEC 47 vs 54, etc.) pointing INTO ranges consumed by PRD-010/ARCH-010/IMP-011; counters advanced past all artifact maxima. New CONS-ERR-004 check scans state/artifacts for planning IDs and errors when a counter is at or behind the used maximum; proven against the real pre-fix value (IMP-TASK rewound to 89 -> finding fires).",
      "linked_ids": [
        "REQ-107",
        "TRK-117"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python -m unittest tests.test_state_consistency_check",
          "outcome": "14 tests OK (2 new)"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 865 tests -- OK"
        },
        {
          "command": "rewind IMP-TASK counter to 89 and run checker",
          "outcome": "CONS-ERR-004 fires naming IMP-TASK"
        }
      ]
    },
    {
      "id": "EV-111",
      "type": "validation",
      "summary": "IMP-TASK-091 stage 1 verified: the UTCP manual is the complete source of truth. utcp.json manual 2.0.0 covers all 57 tools (12 cli-native + 45 bridged via official McpCallTemplate shape from @utcp/mcp). New tests prove: manual == catalog on both transports; bridged descriptions/schemas equal the server's generated projection (mcp/tool-metadata.json, node-gated live parity); every non-read capability tool uses an mcp template against the validated server and carries cap:mutating; cli tools stay cli. Installer ships tool-metadata.json beside the server.",
      "linked_ids": [
        "REQ-107",
        "TRK-117"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python -m unittest tests.test_utcp_first_catalog tests.test_prd_tools tests.test_mcp_server",
          "outcome": "30 tests OK (6 new UTCP-first)"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 871 tests -- OK"
        }
      ],
      "limitations": "Bridge round-trip via @utcp/mcp-bridge and hand-written server retirement remain open IMP-TASK-091 scope."
    },
    {
      "id": "EV-112",
      "type": "validation",
      "summary": "PRD Plugin 0.16.5 and 0.16.6 shipped: five release gates green for each, merged to main, v0.16.5 and v0.16.6 tags pushed (tag push triggers the npm publication workflow). 0.16.5 = registry planning-counter guard; 0.16.6 = UTCP-first stage 1 (complete 57-tool manual, generated MCP metadata projection, installer delivery).",
      "linked_ids": [
        "TRK-117",
        "REQ-107",
        "CHG-087",
        "CHG-088"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "git push origin main && git push origin v0.16.5 / v0.16.6",
          "outcome": "main at 87808bd; both tags pushed"
        }
      ]
    },
    {
      "id": "EV-113",
      "type": "validation",
      "summary": "IMP-TASK-091 bridge parity verified with the OFFICIAL SDK: @utcp/mcp-bridge 1.1.0 mounted the pure manual from a file source in a freshly installed repo, listed all 57 namespaced tools, executed a native cli read (prd_plugin.status returned live autonomy state) and an mcp-bridged validated server call (prd_plugin.prd_status returned requests_by_status). Debugging grounded three contract facts now encoded in code+tests: strict UtcpManual shape (pure manual vs hub-feed static manifest), per-manual allowed_communication_protocols, and mcpServers keyed by the mount name.",
      "linked_ids": [
        "REQ-107",
        "TRK-117"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python -m unittest tests.test_utcp_first_catalog -v",
          "outcome": "7 tests OK incl. BridgeParityTests round-trip"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 873 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-114",
      "type": "validation",
      "summary": "PRD Plugin 0.16.7 shipped: five release gates green, merged to main (f9f1669), v0.16.7 tag pushed (the tag push triggers the npm publication workflow). Official @utcp/mcp-bridge parity is now CI-gated on every push via npm ci.",
      "linked_ids": [
        "TRK-117",
        "REQ-107",
        "CHG-089",
        "EV-113"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "git push origin main && git push origin v0.16.7",
          "outcome": "main at f9f1669; tag v0.16.7 pushed"
        }
      ]
    },
    {
      "id": "EV-115",
      "type": "validation",
      "summary": "REQ-106 verified: prd_import_request imports an inbox package end-to-end in an installed repo — record carries origin_repo/source_request_id/upstream provenance, lands proposed, duplicate re-import rejected naming the existing id, path traversal outside .prd_plugin/inbox refused. The tool projected into the UTCP manual automatically (58 entries) via the generated metadata; MCP count 46 pinned.",
      "linked_ids": [
        "REQ-106",
        "REQ-107",
        "TRK-117"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python -m unittest tests.test_mcp_server tests.test_utcp_first_catalog tests.test_prd_tools",
          "outcome": "33 tests OK incl. new import e2e"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 874 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-116",
      "type": "validation",
      "summary": "TRK-117 complete and shipped across 0.16.5-0.16.8 (all four tags pushed; the tag push triggers npm publication). Audit: bespoke MCP server predated the 2026-07-03 UTCP-first direction and was never migrated (REQ-107). Delivered: registry planning-counter guard; complete 58-entry UTCP manual as source of truth; generated MCP metadata projection; official @utcp/mcp-bridge round-trip parity, CI-gated; validated prd_import_request inbox intake (REQ-106 implemented). Remaining durable scope — staged retirement of the hand-written server — stays tracked as IMP-TASK-091 (in_progress) in IMP-011.",
      "linked_ids": [
        "TRK-117",
        "REQ-106",
        "REQ-107",
        "EV-110",
        "EV-111",
        "EV-113",
        "EV-115"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "git push origin v0.16.5 v0.16.6 v0.16.7 v0.16.8 (per-release)",
          "outcome": "main at b1c48ca; four release tags pushed, five gates green each"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 874 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-117",
      "type": "validation",
      "summary": "REQ-108 verified: all 13 /prd-* administration commands have generated source-command-* skills across all seven hub mirror copies, registered for codex+opencode in both skill-install-scope manifests, with the parity test enforcing command<->skill existence, content derivation, mirror byte-equality, host registration, and slash-command routing in frontmatter. Discoverability proven live: the generated skills appeared in the working session's own skill list immediately after generation. prd_import_request alias normalization verified by test and by the real REQ-092 import (compat -> compatibility).",
      "linked_ids": [
        "REQ-108",
        "TRK-118"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python -m unittest tests.test_command_skill_parity",
          "outcome": "6 tests OK"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 881 tests -- OK (7 new)"
        }
      ]
    },
    {
      "id": "EV-118",
      "type": "validation",
      "summary": "PRD Plugin 0.16.9 shipped: five release gates green, merged to main (011781c), v0.16.9 tag pushed (the tag push triggers npm publication). Host-native command parity delivered end to end from inbox report to release; REQ-108 implemented.",
      "linked_ids": [
        "TRK-118",
        "REQ-108",
        "CHG-091",
        "EV-117"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "git push origin main && git push origin v0.16.9",
          "outcome": "main at 011781c; tag v0.16.9 pushed"
        }
      ]
    },
    {
      "id": "EV-119",
      "type": "validation",
      "summary": "REQ-109 verified end to end. Page contract v1: wiki tool list/read return exact UTF-8 Markdown (byte-exact incl. CRLF), title, safe filename, sha256, Commit/Updated provenance; traversal, absolute paths, outside-wiki, non-Markdown, and non-UTF-8 all rejected (13 new tests). Offline viewer: one self-contained HTML file, driven LIVE in a browser — all 25 hub pages listed, index renders (15 sections/tables), Copy button flashed success on clipboard resolve, Download carries a blob URL named after the page. Full suite 894 tests OK.",
      "linked_ids": [
        "REQ-109",
        "TRK-119"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python -m unittest tests.test_wiki_page_contract tests.test_wiki_html_export",
          "outcome": "13 tests OK"
        },
        {
          "command": "browser drive of .prd_plugin/local/wiki-html/index.html (served on 127.0.0.1)",
          "outcome": "copy flash shown after clipboard write resolved; download blob named index.md; 27 nav links"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 894 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-120",
      "type": "validation",
      "summary": "PRD Plugin 0.16.10 shipped: five gates green, merged to main (8e82996), v0.16.10 tag pushed (tag push triggers npm publication). Wiki page contract + offline viewer delivered; REQ-109 implemented.",
      "linked_ids": [
        "TRK-119",
        "REQ-109",
        "CHG-092",
        "EV-119"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "git push origin main && git push origin v0.16.10",
          "outcome": "main at 8e82996; tag v0.16.10 pushed"
        }
      ]
    },
    {
      "id": "EV-121",
      "type": "validation",
      "summary": "REQ-110 verified: --all discovered exactly the 6 workspace repos with PRD Plugin + wiki (AI-Collab-Desktop-Bridge 3 pages, AI-Collab-v3 19, Asset-Foundry 13, GRAPH_LANG 10, prd-plugin 27, visual-context-engine 14), generated each repo's self-contained viewer with a back-link, and wrote all-wikis.html with per-repo cards linking to each viewer via file URIs — driven in a browser (all 6 cards render with counts and correct hrefs) and sibling viewers structurally verified (payload page counts, repo_ids, back-links). 3 new tests; full suite 897 OK. Non-PRD and wiki-less dirs correctly skipped.",
      "linked_ids": [
        "REQ-110",
        "TRK-120"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python scripts/wiki_html_export.py --all",
          "outcome": "6 repos, super index written"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 897 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-122",
      "type": "validation",
      "summary": "PRD Plugin 0.16.11 shipped: five gates green, merged to main (f13263b), v0.16.11 tag pushed (tag push triggers npm publication). Workspace super index live at the hub's .prd_plugin/local/wiki-html/all-wikis.html covering 6 repos.",
      "linked_ids": [
        "TRK-120",
        "REQ-110",
        "CHG-093",
        "EV-121"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "git push origin main && git push origin v0.16.11",
          "outcome": "main at f13263b; tag v0.16.11 pushed"
        }
      ]
    },
    {
      "id": "EV-123",
      "type": "validation",
      "summary": "REQ-111 shipped in 0.16.12 (five gates green, main at 893f127, tag pushed → npm publication). Live super index regenerated: 7 cards including Fork (35 pages) whose viewer is hosted beside the super index; Fork's git tree verified untouched. Discovery keys on wiki/index.md; docs-only and wiki-less dirs skipped; 898 tests OK.",
      "linked_ids": [
        "REQ-111",
        "TRK-121",
        "CHG-093"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python scripts/wiki_html_export.py --all",
          "outcome": "7 repos: 6 plugin repos + Fork (guest, hosted viewer)"
        },
        {
          "command": "git -C D:\\Projects\\Fork status --porcelain | grep wiki-html",
          "outcome": "no output — guest tree untouched"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 898 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-124",
      "type": "validation",
      "summary": "REQ-112 verified: parse_wiki_log extracts dated entries with bodies and lint classification from the shared log convention; export_all combines all 7 wikis' logs into the Changelog tab. Driven live in a browser: #changelog opens the tab, days sorted newest-first (07-16 down), 177 entries total, 54 lint runs hidden by default and revealed by the toggle, first-day badges span AI-Collab-v3, Asset-Foundry, Fork; badges deep-link to each repo's log page. 3 new tests; full suite 901 OK.",
      "linked_ids": [
        "REQ-112",
        "TRK-122"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python -m unittest tests.test_wiki_html_export",
          "outcome": "13 tests OK"
        },
        {
          "command": "browser drive of all-wikis.html#changelog",
          "outcome": "tab active, 177 entries, newest-first, lint toggle works"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 901 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-125",
      "type": "validation",
      "summary": "PRD Plugin 0.16.13 shipped: five gates green, merged to main (a627d40), v0.16.13 tag pushed (tag push triggers npm publication). Live super index regenerated with the Changelog tab; user's bookmark picks it up in place.",
      "linked_ids": [
        "TRK-122",
        "REQ-112",
        "CHG-095",
        "EV-124"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "git push origin main && git push origin v0.16.13",
          "outcome": "main at a627d40; tag v0.16.13 pushed"
        }
      ]
    },
    {
      "id": "EV-126",
      "type": "validation",
      "summary": "REQ-114 verified: 7 new FreshnessTests prove stale open goals never conscript (stop reason names staleness), fresh goals still block, the window honors automation.stop_guard_goal_max_age_days (0 excludes yesterday; default 2 includes it), a session's OWNED goal stays a candidate regardless of age, a fresh goal beats a newer-sorting stale one, and undated legacy records keep old behavior. Config key registered in the prd_config contract and all four config templates; four guard copies byte-identical. Full suite 908 tests OK.",
      "linked_ids": [
        "REQ-114",
        "TRK-123"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python -m unittest tests.test_stop_guard",
          "outcome": "33 tests OK (7 new)"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 908 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-127",
      "type": "validation",
      "summary": "PRD Plugin 0.16.14 shipped: five gates green, merged to main (b4a3d23), v0.16.14 tag pushed (tag push triggers npm publication). Stop-guard freshness window live in all four guard copies and every config template.",
      "linked_ids": [
        "TRK-123",
        "REQ-114",
        "CHG-096",
        "EV-126"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "git push origin main && git push origin v0.16.14",
          "outcome": "main at b4a3d23; tag v0.16.14 pushed"
        }
      ]
    },
    {
      "id": "EV-128",
      "type": "validation",
      "summary": "REQ-115 verified: feature_skill_audit extended with tool parity found exactly the reported drift (20 features undeclared, 15 capabilities unclaimed, 5 post-0.16.0 features missing from the map, 4 stale skill guidances) and now audits clean: status ok, 25 features, all 15 tool-surface capabilities claimed, bidirectional. Method rule landed in completion-gate.md and three lifecycle skills, with the adapted downstream verification variant preserved (clobber trap avoided on second attempt). 4 new policy tests; full suite 912 OK.",
      "linked_ids": [
        "REQ-115",
        "TRK-124"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "python scripts/feature_skill_audit.py --format json",
          "outcome": "status ok, summary all zeros (was 20 high + 15 medium before backfill)"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 912 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-129",
      "type": "validation",
      "summary": "PRD Plugin 0.16.15 shipped: five gates green, merged to main, v0.16.15 tag pushed (tag push triggers npm publication). Tool parity rule live in method, map, and audit.",
      "linked_ids": [
        "TRK-124",
        "REQ-115",
        "CHG-097",
        "EV-128"
      ],
      "created_at": "2026-07-16",
      "commands": [
        {
          "command": "git push origin main && git push origin v0.16.15",
          "outcome": "main merged; tag v0.16.15 pushed"
        }
      ]
    },
    {
      "id": "EV-130",
      "type": "validation",
      "summary": "TRK-125 audit complete and shipped in 0.16.16 (five gates green, main merged, tag pushed; ceremony's new cache-refresh step updated Claude marketplace + user install to 0.16.16 in the same flow). Installs verified: Claude cache 42 skills + 13 commands at correct version; Codex clone declares skills/ with 42 present. Workflows: CHML zero; session.stop/hub.release current; gap closed with the new request.import workflow (13 total, registered in catalog/config/map/skills). Skill bundle versioned via skills-manifest.json (test-enforced). Code anchors: prd_graph indexes stamped IDs (5 tests incl. hub's organic REQ-114 stamp); TDI skill codifies the stamping practice. Full suite 923 tests OK.",
      "linked_ids": [
        "TRK-125"
      ],
      "created_at": "2026-07-17",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 923 tests -- OK"
        },
        {
          "command": "python scripts/prd_graph.py --anchors REQ-114",
          "outcome": "lists guard source files and line numbers"
        },
        {
          "command": "git push origin main && git push origin v0.16.16",
          "outcome": "tag pushed"
        }
      ]
    },
    {
      "id": "EV-131",
      "type": "validation",
      "summary": "Off switch verified end to end in a temp downstream install: profile apply off set hooks.enabled/run_until_done/workflows all False and the Stop dispatcher produced ZERO output (no guard block, no nudge); profile apply balanced restored hooks.enabled True. Full suite 923 tests OK; 44 skills in the regenerated manifest; both new commands + generated skills discoverable live in this session.",
      "linked_ids": [
        "REQ-119",
        "TRK-126"
      ],
      "created_at": "2026-07-18",
      "commands": [
        {
          "command": "prd_config.py profile apply off && prd_hook_dispatch.py --event Stop",
          "outcome": "rc 0, empty output — every hook behavior silenced"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 923 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-132",
      "type": "validation",
      "summary": "PRD Plugin 0.16.17 shipped: five gates green, merged to main, v0.16.17 tag pushed (triggers npm publication); ceremony cache-refresh updated the Claude marketplace and user-scope install in the same flow.",
      "linked_ids": [
        "TRK-126",
        "REQ-119",
        "CHG-098",
        "EV-131"
      ],
      "created_at": "2026-07-18",
      "commands": [
        {
          "command": "git push origin main && git push origin v0.16.17",
          "outcome": "tag pushed; marketplace + user scope refreshed to 0.16.17"
        }
      ]
    },
    {
      "id": "EV-133",
      "type": "validation",
      "summary": "REQ-120/IMP-012 verified. 17 new tests cover the contract (scalar keys, structured-map validation, every rejection case), resolver precedence, fail-closed minting, and the tool surface. E2e in a temp downstream install: evidence-backed mint resolved (batch-and-stop-on-green/EV-478), evidence-less mint refused rc2 with no state mutation, unmapped model resolved {action: raw, source: default}, task-type override beat the wildcard, downstream config audit ok. All CHML audits zero (feature_skill ok, workflow_chml ok, config audit ok 199 settings, state consistency none, gate ok). Full suite 940 tests OK. Tool parity by construction: capability fabric.resolve claimed by feature fabric_model_profile_binding.",
      "linked_ids": [
        "REQ-120",
        "TRK-127"
      ],
      "created_at": "2026-07-18",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 940 tests -- OK"
        },
        {
          "command": "set-fabric-binding e2e (temp install)",
          "outcome": "mint+resolve ok; evidence-less refused; unmapped -> raw"
        },
        {
          "command": "feature_skill_audit + workflow_chml_audit + config audit + gate",
          "outcome": "all CHML zero / ok"
        }
      ]
    },
    {
      "id": "EV-134",
      "type": "validation",
      "summary": "PRD Plugin 0.16.18 shipped: five gates green, merged to main, v0.16.18 tag pushed (triggers npm publication); marketplace and user-scope install refreshed in the ceremony. IMP-012 complete across all three phases with all validations satisfied.",
      "linked_ids": [
        "TRK-127",
        "REQ-120",
        "CHG-099",
        "EV-133"
      ],
      "created_at": "2026-07-18",
      "commands": [
        {
          "command": "git push origin main && git push origin v0.16.18",
          "outcome": "tag pushed; caches refreshed to 0.16.18"
        }
      ]
    },
    {
      "id": "EV-135",
      "type": "validation",
      "summary": "REQ-121 remediation verified by REGISTRY READ-BACK, not intent: publish_verify confirmed prd-plugin@0.16.20 with version_seen=0.16.20 AND dist-tags.latest=0.16.20 (attempt 4 of 20). Two root causes fixed and each proven: (1) CRLF working-tree bytes in hash input (folded to LF); (2) platform-dependent sorted(Path) order — Windows case-insensitive vs Linux case-sensitive — proven by predicting the runner's exact hash 960db238 locally via POSIX-string ordering before shipping. The publish workflow failure emails trace to the same single test failing CI on every main push since v0.16.16. Suite 947 OK; five gates green. v0.16.16-v0.16.19 tags never published; 0.16.20 supersedes them on npm and delivers their full feature set.",
      "linked_ids": [
        "REQ-121",
        "TRK-128"
      ],
      "created_at": "2026-07-18",
      "commands": [
        {
          "command": "python scripts/publish_verify.py --version 0.16.20 --attempts 20 --delay-seconds 30",
          "outcome": "published: true, version_seen 0.16.20, latest_seen 0.16.20, attempts_used 4"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 947 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-136",
      "type": "validation",
      "summary": "REQ-122 shipped and registry-confirmed: publish_verify reports prd-plugin@0.16.21 published true, version_seen 0.16.21, latest_seen 0.16.21 (attempt 4). Runtime binding validation proven by 6 new tests (loopback public binding, missing bind_host, and consent waiver are named errors; valid 0.0.0.0 declaration clean; undeclared runtime untouched). Consent-floor rule landed in decision-policy Part 3, AGENTS.md and CLAUDE.md hub+skeleton, all skill mirrors synced; coverage-map feature service_runtime_bindings claims services.read/mutate. Full suite 953 OK; five gates green.",
      "linked_ids": [
        "REQ-122",
        "TRK-129"
      ],
      "created_at": "2026-07-18",
      "commands": [
        {
          "command": "python scripts/publish_verify.py --version 0.16.21",
          "outcome": "published true, latest 0.16.21, attempts_used 4"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 953 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-137",
      "type": "validation",
      "summary": "Extensions namespace verified by 3 new tests: extensions.goal_budget_mode audits clean, non-object extensions is invalid, automation.goal_budget_mode still warns (strictness preserved). Upstream reply loop closed: MSG replies appended to REQ-120/REQ-121 and the scoped mailbox published into ai-collab-v3's .prd_plugin/mailboxes/prd-plugin/ carrying the full resolution map incl. REQ-134->REQ-120 implemented and REQ-135->REQ-121 implemented. Suite 956 OK.",
      "linked_ids": [
        "REQ-123",
        "TRK-130"
      ],
      "created_at": "2026-07-18",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 956 tests -- OK"
        },
        {
          "command": "python scripts/request_mailbox.py --repo-id ai-collab-v3 --output <their mailboxes dir>",
          "outcome": "mailbox lists REQ-134->REQ-120 implemented, REQ-135->REQ-121 implemented"
        }
      ]
    },
    {
      "id": "EV-138",
      "type": "validation",
      "summary": "PRD Plugin 0.16.22 registry-confirmed: publish_verify reports published true, version and dist-tags.latest both 0.16.22 (attempt 4). Extensions namespace and upstream reply mailbox delivered.",
      "linked_ids": [
        "TRK-130",
        "REQ-123",
        "CHG-102",
        "EV-137"
      ],
      "created_at": "2026-07-18",
      "commands": [
        {
          "command": "python scripts/publish_verify.py --version 0.16.22",
          "outcome": "published true, latest 0.16.22, attempts_used 4"
        }
      ]
    },
    {
      "id": "EV-139",
      "type": "validation",
      "summary": "REQ-124 verified: unanswered_resolutions detector tested (flags terminal imports with no upstream reply; answered/local/non-terminal excluded) and proven live — first hub run found exactly the four historical gaps (REQ-105/108/109/115); after replies + mailbox republish + thread closes, message_check reports status clear with unanswered_resolutions 0 and unresolved_threads 0. Suite 957 OK. Memory written (close-the-upstream-reply-loop); intake skill carries the Close-the-Loop rule across all mirrors.",
      "linked_ids": [
        "REQ-124",
        "TRK-131"
      ],
      "created_at": "2026-07-18",
      "commands": [
        {
          "command": "python -m unittest tests.test_message_check",
          "outcome": "OK (new detector test)"
        },
        {
          "command": "python scripts/message_check.py --config .prd_plugin/config.json",
          "outcome": "status clear; unanswered_resolutions 0"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 957 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-140",
      "type": "validation",
      "summary": "PRD Plugin 0.16.23 registry-confirmed: publish_verify published true, version and latest 0.16.23 (attempt 4). Loop-closure detector, intake rule, memory, and the six cleared historical gaps all shipped.",
      "linked_ids": [
        "TRK-131",
        "REQ-124",
        "CHG-103",
        "EV-139"
      ],
      "created_at": "2026-07-18",
      "commands": [
        {
          "command": "python scripts/publish_verify.py --version 0.16.23",
          "outcome": "published true, latest 0.16.23"
        }
      ]
    },
    {
      "id": "EV-141",
      "type": "validation",
      "summary": "REQ-125 verified against REAL downstream data (temp copy of ai-collab-v3's 135-record requests.json + delivered mailbox; their repo never mutated): 9 pending resolutions applied — REQ-134->REQ-120, REQ-135->REQ-121, REQ-090->REQ-105, REQ-092->REQ-108, REQ-095->REQ-109, REQ-116->REQ-115 all now implemented with upstream_request_id stamped; their local-only REQ-133 correctly untouched; record count 135 before and after (the old code would have planted foreign hub records); second run applied 0 (idempotent). 4 new protocol tests cover source-id resolution, idempotency, unmatched-not-planted, and directory scanning. session.start now runs requests.pull (fail-open). Suite 961 OK.",
      "linked_ids": [
        "REQ-125",
        "TRK-132"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "apply_pending_mailboxes(<temp copy of ai-collab-v3 state>)",
          "outcome": "applied 9, unmatched 0, 135 records unchanged, rerun applied 0"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 961 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-142",
      "type": "validation",
      "summary": "PRD Plugin 0.16.24 registry-confirmed: published true, version and latest 0.16.24 (attempt 4). The downstream half of the resolution loop is shipped — delivered mailboxes now resolve local records and apply automatically at session start.",
      "linked_ids": [
        "TRK-132",
        "REQ-125",
        "CHG-104",
        "EV-141"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python scripts/publish_verify.py --version 0.16.24",
          "outcome": "published true, latest 0.16.24"
        }
      ]
    },
    {
      "id": "EV-143",
      "type": "validation",
      "summary": "REQ-126 verified on the REAL downstream repo with the owner's explicit direction. Before: ai-collab-v3 message_check status attention (outbox 2 stale packages, mailbox_files 1) with REQ-134/REQ-135 still 'proposed'. After running the fixed request_pull --all against it: 9 resolutions applied (REQ-134->REQ-120, REQ-135->REQ-121, REQ-090->REQ-105, REQ-092->REQ-108, REQ-095->REQ-109, REQ-116->REQ-115), 2 outbox packages pruned, 1 consumed mailbox cleared, record count 135 unchanged (no foreign records), their local-only REQ-133 correctly untouched, and their transport now reports STATUS: clear with every counter zero. Their git tree was clean beforehand; only requests.json is modified, left uncommitted for their own ledger. 3 new tests cover pruning, keep-unresolved, and mailbox consumption with unmatched-rows retention. Suite 964 OK.",
      "linked_ids": [
        "REQ-126",
        "TRK-133"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python scripts/request_pull.py --repo-root <ai-collab-v3> --all",
          "outcome": "applied 9, pruned_outbox [REQ-134, REQ-135], consumed_mailboxes 1"
        },
        {
          "command": "python scripts/message_check.py --repo-root <ai-collab-v3>",
          "outcome": "STATUS: clear; outbox 0, mailbox_files 0, unresolved 0, unanswered 0"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 964 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-144",
      "type": "validation",
      "summary": "PRD Plugin 0.16.25 registry-confirmed (published true, latest 0.16.25). The full resolution loop is now closed in all four places it could break: hub reply (REQ-124 detector), downstream record resolution (REQ-125 source-id matching + auto-pull), and transport residue (REQ-126 outbox pruning + mailbox consumption). The real downstream repo reports clear.",
      "linked_ids": [
        "TRK-133",
        "REQ-126",
        "CHG-105",
        "EV-143"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python scripts/publish_verify.py --version 0.16.25",
          "outcome": "published true, latest 0.16.25"
        }
      ]
    },
    {
      "id": "EV-145",
      "type": "validation",
      "summary": "REQ-127 verified. 9 new identity tests: placeholder is a finding for an INSTALLED repo but not for a template (audit gained install context), resolution derives the repo name and never overwrites a real id, workspace_peers treats empty as standalone on both sides, set-identity validates, and a fresh install resolves identity automatically. Applied across the real workspace: graph_lang, asset-foundry, visual-context-engine, ai-collab-desktop-bridge resolved; hub resolved to prd-plugin; the boundary predicate now reads correctly on live data (only AI-Collab-v3 is a peer of itself, everything else standalone=False). Two pre-existing defects surfaced and fixed: substrate drift detection was gated behind 'no findings at all' so any benign advisory silently disabled it (now gated on structural integrity), and hub/template manifest parity asserted byte equality which is now deliberately false (compares modulo identity). Suite 973 OK.",
      "linked_ids": [
        "REQ-127",
        "TRK-134"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python -m unittest tests.test_repo_identity",
          "outcome": "9 tests OK"
        },
        {
          "command": "resolve_repository_identity across D:/Projects/*",
          "outcome": "4 placeholders resolved; boundary predicate correct on live manifests"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 973 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-146",
      "type": "validation",
      "summary": "PRD Plugin 0.16.26 registry-confirmed (published true, latest 0.16.26). Repository identity is real across the workspace and the messaging boundary predicate reads correctly on live manifests — the blocker for addressed routing is cleared.",
      "linked_ids": [
        "TRK-134",
        "REQ-127",
        "CHG-106",
        "EV-145"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python scripts/publish_verify.py --version 0.16.26",
          "outcome": "published true, latest 0.16.26"
        }
      ]
    },
    {
      "id": "EV-147",
      "type": "validation",
      "summary": "REQ-128 verified: CRAFTES lands in all 14 skill copies (decision-policy + deterministic-workflows across 7 mirrors each) and all four always-in-force docs (hub + skeleton AGENTS.md/CLAUDE.md), with Secure defined by four testable demands. Wiki article renamed and given a 'Secure: where it matters' section distinguishing it from the consent floor, listing six boundary classes where it is load-bearing and stating that 'not applicable, no boundary crossed' is a legitimate answer. Tests assert the seven terms plus the three demand phrases on whitespace-normalized prose (line wrapping and markdown emphasis previously made naive substring assertions brittle). Append-only history preserved: .prd_plugin/state/*, templates/releases.json and raw/* still say CRAFTE, because rewriting them would falsify what the bar was at the time. Suite 975 OK.",
      "linked_ids": [
        "REQ-128",
        "TRK-135"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python -m unittest tests.test_decision_policy tests.test_grounding_estimation",
          "outcome": "33 tests OK (2 new Secure tests)"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 975 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-148",
      "type": "validation",
      "summary": "PRD Plugin 0.16.27 registry-confirmed (published true, latest 0.16.27). CRAFTES is live: Secure ships in every skill copy, both always-in-force docs, hub and downstream skeleton, with the wiki definition and where-it-matters guidance.",
      "linked_ids": [
        "TRK-135",
        "REQ-128",
        "CHG-107",
        "EV-147"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python scripts/publish_verify.py --version 0.16.27",
          "outcome": "published true, latest 0.16.27"
        }
      ]
    },
    {
      "id": "EV-149",
      "type": "validation",
      "summary": "REQ-130 verified. Root cause proven from the original fixture: visibility 'upstream' means hub-only ('hub-only note' in the pre-existing pull test), so request_mailbox was right to strip it and my REQ-124 intake rule was wrong to prescribe it. Three fixes: unanswered_resolutions now clears only on a deliverable (repo/public) reply and names the undeliverable reason; request_mailbox reports withheld counts plus silent_resolutions and warns at publish; the intake skill prescribes --visibility repo and explains the direction. Nine affected replies redelivered (REQ-029/056/105/108/109/115/120/121/129) with original bodies preserved — the hub-only originals are kept, history not rewritten. The new warning caught REQ-056, which my manual scan missed. Republished mailbox now carries 9 rows with bodies and silent_resolutions is empty; REQ-129's 3015-char question set finally reaches them. Suite 978 OK.",
      "linked_ids": [
        "REQ-130",
        "TRK-136"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python -m unittest tests.test_message_check tests.test_request_protocol",
          "outcome": "19 tests OK (3 new)"
        },
        {
          "command": "python scripts/request_mailbox.py --repo-id ai-collab-v3",
          "outcome": "silent_resolutions [] ; 9 rows carry message bodies"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 978 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-150",
      "type": "validation",
      "summary": "PRD Plugin 0.16.28 registry-confirmed (published true, latest 0.16.28). Nine redelivered reply bodies are in ai-collab-v3's mailbox, including the 3015-char REQ-129 question set; silent_resolutions is empty.",
      "linked_ids": [
        "TRK-136",
        "REQ-130",
        "CHG-108",
        "EV-149"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python scripts/publish_verify.py --version 0.16.28",
          "outcome": "published true, latest 0.16.28"
        }
      ]
    },
    {
      "id": "EV-151",
      "type": "validation",
      "summary": "REQ-131 verified. Two defects fixed: (1) silent-delivery detection now covers BODY_DEPENDENT_STATUSES — terminal statuses plus needs_info — so a question delivered without its body is flagged and warned at publish; previously only terminal statuses were checked and ai-collab's exact case slipped through. (2) append_reply clears needs_info only when the reply is inbound (visibility 'upstream', travelling to the hub); an outbound reply no longer downgrades our own blocked state, which is how REQ-129 silently became in_review. REQ-129 restored to needs_info. 3 new tests; suite 981 OK.",
      "linked_ids": [
        "REQ-131",
        "TRK-137"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python -m unittest tests.test_request_protocol tests.test_message_check",
          "outcome": "22 tests OK (3 new)"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 981 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-152",
      "type": "validation",
      "summary": "PRD Plugin 0.16.29 registry-confirmed (published true, latest 0.16.29). Mailbox republished: silent_resolutions empty, REQ-129 delivered as needs_info with its full 3015-char question body, REQ-131 resolution delivered with 2591 chars of reasoning.",
      "linked_ids": [
        "TRK-137",
        "REQ-131",
        "CHG-109",
        "EV-151"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python scripts/publish_verify.py --version 0.16.29",
          "outcome": "published true, latest 0.16.29"
        }
      ]
    },
    {
      "id": "EV-153",
      "type": "validation",
      "summary": "REQ-132 verified: deliver_reply appends, regenerates the sanitized package, writes the destination inbox record, then READS IT BACK and compares message id plus sha256 body digest before reporting success. Three tests prove the behaviours their report demanded: a delivered reply verifies id+digest against the artifact on disk; a body referencing local runtime paths raises DeliveryError naming the rejecting rule with NOTHING delivered (previously dropped silently while the caller was told success); and a second reply to an already-submitted request UPDATES the same package rather than being skipped (both bodies present, in order). CLI --deliver exits 2 on rejection. Intake skill documents it. Suite 984 OK.",
      "linked_ids": [
        "REQ-132",
        "TRK-138"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python -m unittest tests.test_request_protocol",
          "outcome": "20 tests OK (3 new)"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 984 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-154",
      "type": "validation",
      "summary": "PRD Plugin 0.16.30 registry-confirmed (published true, latest 0.16.30). All three of ai-collab-v3's open requests are answered with full bodies delivered into their mailbox and verified on disk: REQ-138->REQ-129 needs_info 3015 chars (the six journal-contract questions), REQ-139->REQ-131 implemented 2591 chars, REQ-140->REQ-132 implemented 1955 chars. Eleven rows carry deliverable bodies; silent_resolutions empty.",
      "linked_ids": [
        "TRK-138",
        "REQ-132",
        "CHG-110",
        "EV-153"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python scripts/publish_verify.py --version 0.16.30",
          "outcome": "published true, latest 0.16.30"
        },
        {
          "command": "read-back of ai-collab-v3 mailbox.json",
          "outcome": "REQ-129 3015 chars, REQ-131 2591 chars, REQ-132 1955 chars; silent_resolutions []"
        }
      ]
    },
    {
      "id": "EV-155",
      "type": "validation",
      "summary": "REQ-133/REQ-134 verified. Outbound: every reply is written with delivery.state pending (hub-only notes are not_outbound and never counted); flush_pending_replies republishes each origin's mailbox and marks delivered ONLY for message ids read back from the published artifact; an unreachable destination leaves the reply pending and is reported; session.start flushes automatically; message_check counts replies pending delivery. Inbound: reconcile_inbox merges package updates into canonical requests by origin_repo + source_request_id, idempotent, clearing needs_info when the asked party answers, and reports unmatched packages as new intake rather than merging them. Proven on real data: reconcile recovered ai-collab-v3's 9967-char MSG-004 into REQ-129 (5 messages reconciled across 3 requests), and the reply to it was delivered through the new flush with the body verified on disk in their repo (3763 chars). 6 new tests; suite 988 OK.",
      "linked_ids": [
        "REQ-133",
        "REQ-134",
        "TRK-139"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python -m unittest tests.test_request_protocol",
          "outcome": "26 tests OK (6 new)"
        },
        {
          "command": "reconcile_inbox('.')",
          "outcome": "reconciled 5, updated REQ-129/132/003"
        },
        {
          "command": "flush_pending_replies + read-back of their mailbox",
          "outcome": "delivered 1, verified 3763 chars present in ai-collab-v3 mailbox"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 988 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-156",
      "type": "validation",
      "summary": "REQ-134 regression found by the suite and fixed before release. The first cut of reconcile_inbox deduped inbound messages on (local id, body) and set thread.status unconditionally. Both were wrong: message ids are allocated PER REPO, so a peer's MSG-005 collides with ours while a message they EDIT keeps its id and looks new — the merge therefore forked revised messages into near-identical twins (MSG-002-inbox, MSG-005-inbox, MSG-001-inbox) and reopened REQ-003, a request resolved back at 0.5.x, plus REQ-132. Identity is now provenance (origin_repo, their message id) with a fresh local id allocated from our own sequence; a revision updates in place and is reported as `revised`; legacy unstamped messages are adopted by body so upgrading does not double them; and a terminal request keeps its resolution while still merging the message. Corrupted live state was repaired against the committed record: 3 forked twins removed, REQ-003 thread restored to resolved, REQ-132 to closed, with REQ-129's recovered 9967-char answer confirmed intact.",
      "linked_ids": [
        "REQ-134",
        "TRK-139"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python -m unittest discover -s tests (before fix)",
          "outcome": "Ran 990 -- FAILED (1): test_persistent_zeusgrid_helper_script_bug_is_thread_update, thread.status 'open' != 'resolved'"
        },
        {
          "command": "reconcile_inbox x3 on live state after fix",
          "outcome": "run1 reconciled=3 revised=0; run2 and run3 no-ops; state identical across runs (idempotent)"
        },
        {
          "command": "python -m unittest discover -s tests (after fix)",
          "outcome": "Ran 993 tests -- OK (3 new regression tests)"
        }
      ]
    },
    {
      "id": "EV-157",
      "type": "validation",
      "summary": "0.16.31 published and confirmed by npm registry read-back, not by intent: publish_verify reports published=true, version_seen=0.16.31, latest_seen=0.16.31 after 4 attempts. Release gates were green before the tag (release_check ok, prd_gate ok, state_consistency_check ok, 993 unit tests OK, 12 system tests passed / 6 skipped, py_compile clean) and message_check reports 0 replies pending delivery, 0 unanswered resolutions and 0 outbox packages.",
      "linked_ids": [
        "REQ-133",
        "REQ-134",
        "TRK-139"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python scripts/release_check.py",
          "outcome": "base 0.16.30 -> head 0.16.31, findings: None"
        },
        {
          "command": "python scripts/prd_gate.py check",
          "outcome": "Status ok, findings None"
        },
        {
          "command": "python scripts/state_consistency_check.py",
          "outcome": "Status ok, findings None"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 993 tests -- OK"
        },
        {
          "command": "python -m pytest system_tests -q",
          "outcome": "12 passed, 6 skipped"
        },
        {
          "command": "git push origin main && git push origin v0.16.31",
          "outcome": "532d26d..e2d6639 main -> main; [new tag] v0.16.31"
        },
        {
          "command": "python scripts/publish_verify.py --version 0.16.31",
          "outcome": "published=true, version_seen=0.16.31, latest_seen=0.16.31, attempts_used=4"
        }
      ]
    },
    {
      "id": "EV-158",
      "type": "validation",
      "summary": "journal.* contract v1 implemented and verified. All seven accepted activation keys ship in every config template with the agreed safe defaults (enabled false, capture off, reflections off, prompt_recall off, retention archive-only, protected_read_audit true, schema_version 1), so installing the family changes no behaviour until deliberately switched on. prd_config describe journal.enabled now resolves instead of returning unknown setting — the exact command in their report. Feature keys declare journal.enabled as a dependency for dependency-aware effective state. retention.mode is a closed enum: setting it to 'delete' is refused and the stored value is unchanged, so time-based destructive deletion is not selectable. journal_contract_state implements the partial-family rule fail-closed: absent entirely reports unavailable, partially present reports invalid and names what is missing, and both leave operations_permitted false; only a complete family with a supported schema version permits operations. Exposed as `prd_config.py journal-contract`.",
      "linked_ids": [
        "REQ-135",
        "TRK-140"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python -m unittest tests.test_unified_config (before)",
          "outcome": "FAILED (errors=4): module prd_config has no attribute journal_contract_state; journal.schema_version not in catalog"
        },
        {
          "command": "python scripts/prd_config.py describe journal.enabled",
          "outcome": "resolves: type bool, default false, category journal, activation runtime"
        },
        {
          "command": "python scripts/prd_config.py set journal.retention.mode delete",
          "outcome": "refused: must be one of ['archive-only']; get returns archive-only unchanged"
        },
        {
          "command": "python scripts/prd_config.py journal-contract",
          "outcome": "state=valid, operations_permitted=true, all 7 keys present"
        },
        {
          "command": "python scripts/prd_config.py audit",
          "outcome": "206 settings, unclassified 0, unknown 0, invalid 0"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 997 tests -- OK (4 new)"
        }
      ]
    },
    {
      "id": "EV-159",
      "type": "validation",
      "summary": "0.16.32 published and confirmed by npm registry read-back: published=true, version_seen=0.16.32, latest_seen=0.16.32 after 4 attempts. All release gates were green before the tag (release_check ok, prd_gate ok, state_consistency_check ok, 997 unit tests OK, 12 system tests passed / 6 skipped). The resolution was then delivered to ai-collab-v3 through the 0.16.31 flush and verified by reading their mailbox back from disk: 2894 chars present, 0 pending. The reply also corrects the REQ-129 message that named 0.16.31 as the journal release before the work existed.",
      "linked_ids": [
        "REQ-135",
        "TRK-140"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python scripts/release_check.py",
          "outcome": "base 0.16.31 -> head 0.16.32, findings: None"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 997 tests -- OK"
        },
        {
          "command": "git push origin main && git push origin v0.16.32",
          "outcome": "a9a5d61..97c4336 main -> main; [new tag] v0.16.32"
        },
        {
          "command": "python scripts/publish_verify.py --version 0.16.32",
          "outcome": "published=true, version_seen=0.16.32, latest_seen=0.16.32"
        },
        {
          "command": "request_reply flush + mailbox read-back",
          "outcome": "delivered 1, undeliverable 0, pending 0; 2894 chars verified in their mailbox"
        }
      ]
    },
    {
      "id": "EV-160",
      "type": "validation",
      "summary": "REQ-136 verified end to end against a real peer, not a fixture. prd_list_destinations resolves ai-collab-v3 as reachable; filing with target_repo wrote REQ-137.json into their inbox and read it back to confirm; the package carries origin_repo=prd-plugin, source_request_id=REQ-137 and scope=peer_submission. A deliberate probe to an undeclared destination refused delivery, named the requests.peers fix, and left the filing intact (REQ-138, since closed). Two defects were found and fixed during verification: (1) reusing build_upstream_submission for peer traffic stripped every repo-visibility body, the same directional failure that delivered nine empty replies, so a separate build_peer_package carries the repo-facing set and hub-private 'upstream' messages provably do not travel; (2) target_repo predates this feature and already marks who an IMPORTED request was FOR, so the first flush re-sent closed REQ-029 back to its own origin - delivery is now restricted to requests this repo authored, non-terminal, not self-addressed, and not already delivered, and the erroneous package was removed from their inbox. Four drift guards then caught unregistered surface (script classification, UTCP catalog, tool count, feature coverage) and all were closed rather than suppressed.",
      "linked_ids": [
        "REQ-136",
        "TRK-141",
        "DEC-012"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "prd_list_destinations",
          "outcome": "ai-collab-v3 reachable=true, same_workspace=false"
        },
        {
          "command": "prd_file_request(target_repo='ai-collab-v3')",
          "outcome": "REQ-137 delivered=true to D:\\Projects\\AI-Collab-v3\\.prd_plugin\\inbox\\prd-plugin\\incoming\\REQ-137.json, verified on disk"
        },
        {
          "command": "prd_file_request(target_repo='no-such-repo')",
          "outcome": "delivered=false, state=undeclared, filing preserved as REQ-138"
        },
        {
          "command": "request_routing.py flush (after guards)",
          "outcome": "delivered 1 (REQ-137 only); 7 correctly refused: not_ours_to_send / self_addressed / undeclared"
        },
        {
          "command": "request_routing.py flush (second run)",
          "outcome": "delivered 0 - delivery stamp holds"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1012 tests -- OK (15 new)"
        },
        {
          "command": "python -m pytest system_tests -q",
          "outcome": "12 passed, 6 skipped"
        },
        {
          "command": "prd_gate.py check / state_consistency_check.py / prd_config.py audit",
          "outcome": "ok / ok / 207 settings, 0 unknown, 0 invalid"
        }
      ]
    },
    {
      "id": "EV-161",
      "type": "validation",
      "summary": "0.16.33 published and confirmed by npm registry read-back: published=true, version_seen=0.16.33, latest_seen=0.16.33. All gates green before the tag (release_check ok over 32 changed files, prd_gate ok, state_consistency ok, config audit 207 settings / 0 unknown / 0 invalid, 1012 unit tests OK, 12 system tests passed).",
      "linked_ids": [
        "REQ-136",
        "TRK-141"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python scripts/release_check.py",
          "outcome": "head 0.16.33, 32 files, findings None"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1012 tests -- OK"
        },
        {
          "command": "git push origin main && git push origin v0.16.33",
          "outcome": "18838d1..3f1aa59 main -> main; [new tag] v0.16.33"
        },
        {
          "command": "python scripts/publish_verify.py --version 0.16.33",
          "outcome": "published=true, latest_seen=0.16.33"
        }
      ]
    },
    {
      "id": "EV-162",
      "type": "validation",
      "summary": "REQ-139 verified and published. Bounded is stated on all twelve surfaces that carry the bar (both always-in-force docs, the decision-policy skill and its six mirrors, the repo-skeleton copies, and the wiki), and six new tests pin it: every surface says CRAFTESB and names Bounded; no surface states a duplicated dimension (the 0.16.27 edit had shipped 'Efficient - Secure - Secure' to four docs); Bounded carries a falsifiable test rather than a virtue rating; it names the concrete scope-inflation patterns; it explicitly does not license under-delivering; and 'without reducing scope' is gone from every normative statement. Two pre-existing tests that pinned the OLD wording were updated rather than deleted. Published and confirmed by registry read-back.",
      "linked_ids": [
        "REQ-139",
        "TRK-142",
        "DEC-013"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python -m unittest tests.test_decision_policy (before)",
          "outcome": "FAILED - BoundedDimensionTests absent, surfaces still stated CRAFTES"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1018 tests -- OK (6 new pinning tests)"
        },
        {
          "command": "python -m pytest system_tests -q",
          "outcome": "12 passed, 6 skipped"
        },
        {
          "command": "release_check / prd_gate / state_consistency",
          "outcome": "None / ok / ok"
        },
        {
          "command": "git push origin main && git push origin v0.16.34",
          "outcome": "2a6b109..7ac41c7 main -> main; [new tag] v0.16.34"
        },
        {
          "command": "python scripts/publish_verify.py --version 0.16.34",
          "outcome": "published=true, version_seen=0.16.34, latest_seen=0.16.34"
        }
      ]
    },
    {
      "id": "EV-163",
      "type": "validation",
      "summary": "REQ-140 verified against the real machine and published as 0.16.35. Reproducing the actual failure state (repo 0.16.34, host install 0.16.30 pinned at b989cd3) the check now reports repo update_available=false AND host_plugin.update_available=true with the fix named - the signal that did not exist when the owner found it by hand. Wired on all three check() return paths and on the cache-only status() the nudge and /prd-status render, because a check nobody sees does not fix 'nothing told me'. Fail-open verified: absent install, malformed record, and unrelated plugins all return None rather than erroring, and an unknown latest version never yields a staleness verdict. Both channels are now in sync on this machine at 0.16.35. Notably the trap was already documented in the wiki on 2026-07-16 with the exact fix commands and recurred anyway, which is the evidence that a note is not a control.",
      "linked_ids": [
        "REQ-140",
        "TRK-143"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python -m unittest tests.test_host_plugin_version (before)",
          "outcome": "AttributeError: module prd_version_check has no attribute host_plugin_version"
        },
        {
          "command": "with_host_plugin against simulated 0.16.30 host, 0.16.34 latest",
          "outcome": "repo update_available=false; host_plugin.update_available=true; reason names `claude plugin update` + restart"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1027 tests -- OK (9 new)"
        },
        {
          "command": "python -m pytest system_tests -q",
          "outcome": "12 passed, 6 skipped"
        },
        {
          "command": "python scripts/publish_verify.py --version 0.16.35",
          "outcome": "published=true, version_seen=0.16.35, latest_seen=0.16.35"
        },
        {
          "command": "claude plugin update prd-plugin@prd-plugin",
          "outcome": "updated 0.16.34 -> 0.16.35 for scope user"
        },
        {
          "command": "prd_version_check.check('.', force=True) on the real machine",
          "outcome": "repo 0.16.35, npm latest 0.16.35, host 0.16.35, both channels in sync"
        }
      ]
    },
    {
      "id": "EV-164",
      "type": "validation",
      "summary": "REQ-141 verified. The UI ships in two modes from one document: a static snapshot (prd_ui_export) that reaches nothing, and a live control surface (prd_ui_serve) where the toggles actually write. Verified against the real repo: all 107 toggles render in 13 collapsible groups, each with its description, as 55 switches, 11 dropdowns and 41 read-only values; 26 carry a 'new session' warning. Toggling drift.monitoring.enabled through the HTTP surface changed the value on disk and was then reverted to its prior value. Refusals hold at the HTTP layer because the server reuses prd_config.set_toggle rather than reimplementing validation: retention.mode=delete, an unknown key, and autonomy_level=cowboy all return 400 with the catalog's own message and leave state unchanged. Styling replicates ai-collab-v3's theme tokens (teal accent, 8px radius, dark-first) because an iframe cannot inherit the host stylesheet, and ?theme=dark|light lets the shell drive the theme. Security shape: loopback-only with a non-loopback bind refused outright, no static file handler (unknown paths 404), and frame-ancestors limited to local origins.",
      "linked_ids": [
        "REQ-141",
        "TRK-144"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python -m unittest tests.test_prd_ui_export tests.test_prd_ui_serve",
          "outcome": "30 tests OK"
        },
        {
          "command": "POST /api/toggle drift.monitoring.enabled=true",
          "outcome": "200; value True on disk via prd_config.get; reverted to False afterwards"
        },
        {
          "command": "POST /api/toggle journal.retention.mode=delete",
          "outcome": "400 'must be one of [archive-only]'; stored value unchanged"
        },
        {
          "command": "render served page in a JS engine",
          "outcome": "13 groups, 107 rows, 55 switches, 11 selects, 26 new-session warnings, theme honoured"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1057 tests -- OK"
        },
        {
          "command": "prd_gate.py check / state_consistency_check.py",
          "outcome": "ok / ok"
        }
      ]
    },
    {
      "id": "EV-165",
      "type": "validation",
      "summary": "0.16.36 published and confirmed by npm registry read-back (version_seen and latest_seen 0.16.36), host plugin refreshed 0.16.35 -> 0.16.36, and the embed contract delivered to ai-collab-v3 as REQ-142 with the package verified on disk in their inbox. Gates green before the tag: 1057 unit tests, 12 system tests passed / 6 skipped, release_check and prd_gate and state_consistency all clean.",
      "linked_ids": [
        "REQ-141",
        "TRK-144"
      ],
      "created_at": "2026-07-19",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1057 tests -- OK"
        },
        {
          "command": "python -m pytest system_tests -q",
          "outcome": "12 passed, 6 skipped"
        },
        {
          "command": "git push origin main && git push origin v0.16.36",
          "outcome": "418fe30..dc55a54 main -> main; [new tag] v0.16.36"
        },
        {
          "command": "python scripts/publish_verify.py --version 0.16.36",
          "outcome": "published=true, latest_seen=0.16.36"
        },
        {
          "command": "claude plugin update prd-plugin@prd-plugin",
          "outcome": "updated 0.16.35 -> 0.16.36 for scope user"
        },
        {
          "command": "prd_file_request(target_repo='ai-collab-v3')",
          "outcome": "REQ-142 delivered=true, package verified in their inbox"
        }
      ]
    },
    {
      "id": "EV-166",
      "type": "validation",
      "summary": "REQ-143 implemented and verified. project-systematic-debugging is now a bounded loop: three consecutive finds where each fix WORKED and each revealed another trips a breaker whose diagnosis is that the model of the system is wrong, followed by four ordered steps - re-ground (assumed versus actual, both sides of every boundary), research local AND web (both required), re-plan for the bug class not the next symptom, implement the plan with tests. Reset conditions are stated so a passing fix does not clear the counter. The rule is grounded in a real episode in this repo rather than an abstraction. Propagated to all six host mirrors and surfaced in the decision-policy router, which every task consults, because an agent mid-whack-a-mole has usually stopped re-reading the debugging skill. 10 new tests pin the threshold, the finds-not-failures distinction, step order, the both-sources rule, reset conditions, and mirror parity.",
      "linked_ids": [
        "REQ-143",
        "TRK-145"
      ],
      "created_at": "2026-07-20",
      "commands": [
        {
          "command": "python -m unittest tests.test_debug_loop (before)",
          "outcome": "FAILED - no re-ground/research/re-plan steps, no threshold, four-phase one-shot"
        },
        {
          "command": "python -m unittest tests.test_debug_loop",
          "outcome": "Ran 10 tests -- OK"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1067 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-167",
      "type": "validation",
      "summary": "0.16.37 published and registry-confirmed (version_seen and latest_seen 0.16.37), and the host plugin refreshed 0.16.36 -> 0.16.37 so the new debugging loop is live in Claude Desktop. Gates green before the tag: 1067 unit tests, 12 system tests passed / 6 skipped, release_check, prd_gate and state_consistency all clean.",
      "linked_ids": [
        "REQ-143",
        "TRK-145"
      ],
      "created_at": "2026-07-20",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1067 tests -- OK"
        },
        {
          "command": "python -m pytest system_tests -q",
          "outcome": "12 passed, 6 skipped"
        },
        {
          "command": "git push origin main && git push origin v0.16.37",
          "outcome": "2f1c190..4ddbb58 main -> main; [new tag] v0.16.37"
        },
        {
          "command": "python scripts/publish_verify.py --version 0.16.37",
          "outcome": "published=true, latest_seen=0.16.37"
        },
        {
          "command": "claude plugin update prd-plugin@prd-plugin",
          "outcome": "updated 0.16.36 -> 0.16.37 for scope user"
        }
      ]
    },
    {
      "id": "EV-168",
      "type": "validation",
      "summary": "REQ-144 implemented and verified. Unrelated finds are parked as REQ-* linked to the episode rather than chased, using the existing record mechanism so the note survives the session and appears in prd_status and the UI as open work - a scratchpad line would not. Related versus unrelated is decidable (same subsystem, boundary, data path, or plausible shared root cause) and uncertainty breaks toward RELATED so it fails toward stopping and re-grounding. Explicitly closed the loophole where mislabelling a related bug as unrelated would keep the breaker's counter at zero. The loop-back is enforced at the completion gate, not left as intent: project-verification-before-completion now requires parked findings to be filed and visible before a completion claim. Consistent with the Bounded dimension of CRAFTESB, which already says adjacent problems get filed rather than built. 7 new tests. A real regression was caught during this change and fixed rather than parked because it was related: blind mirror-syncing clobbered the deliberately divergent DOWNSTREAM variant of the verification skill, replacing 'do not run gap_audit.py / release_check.py / local_workflow_check.py' with instructions to run them. The existing drift guard caught it immediately, so no new mechanism was warranted.",
      "linked_ids": [
        "REQ-144",
        "TRK-146",
        "REQ-143"
      ],
      "created_at": "2026-07-20",
      "commands": [
        {
          "command": "python -m unittest tests.test_debug_loop (before)",
          "outcome": "FAILED (6) - no parking rule"
        },
        {
          "command": "python -m unittest tests.test_debug_loop",
          "outcome": "Ran 17 tests -- OK (7 new)"
        },
        {
          "command": "python -m unittest discover -s tests (after blind mirror sync)",
          "outcome": "FAILED (4): downstream verification skill directed agents to hub-only scripts"
        },
        {
          "command": "restore downstream variants + apply addition only",
          "outcome": "Ran 1074 tests -- OK; 'Do not run gap_audit' preserved downstream"
        }
      ]
    },
    {
      "id": "EV-169",
      "type": "validation",
      "summary": "0.16.38 published and registry-confirmed (version_seen and latest_seen 0.16.38), and the host plugin refreshed 0.16.37 -> 0.16.38 so the parking rule is live in Claude Desktop. Gates green before the tag: 1074 unit tests, 12 system tests passed / 6 skipped, release_check, prd_gate and state_consistency all clean.",
      "linked_ids": [
        "REQ-144",
        "TRK-146"
      ],
      "created_at": "2026-07-20",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1074 tests -- OK"
        },
        {
          "command": "python -m pytest system_tests -q",
          "outcome": "12 passed, 6 skipped"
        },
        {
          "command": "git push origin main && git push origin v0.16.38",
          "outcome": "67ddca8..ff963ef main -> main; [new tag] v0.16.38"
        },
        {
          "command": "python scripts/publish_verify.py --version 0.16.38",
          "outcome": "published=true, latest_seen=0.16.38"
        },
        {
          "command": "claude plugin update prd-plugin@prd-plugin",
          "outcome": "updated 0.16.37 -> 0.16.38 for scope user"
        }
      ]
    },
    {
      "id": "EV-170",
      "type": "validation",
      "summary": "Wiki brought up to date with the work shipped in 0.16.31-0.16.38. Four raw source notes recorded, two existing articles merged into (Request Intake gains delivery state, inbound reconcile and peer routing; Unified Configuration gains the journal contract), two already-edited articles re-stamped to the current commit, and two new articles compiled (The PRD Plugin UI; Debugging as a Bounded Loop). Index and log updated for all six ingests, link lint clean (1 auto-fixed). Tracking state was already green throughout: state_consistency_check ok, prd_gate ok, 0 stale, 0 open health, no active goals. A malformed-row bug in the index (a duplicated date column from the update regex) and a stale index summary still advertising the seven-part CRAFTES bar were both caught and fixed during verification.",
      "linked_ids": [
        "REQ-141",
        "REQ-143",
        "REQ-144"
      ],
      "created_at": "2026-07-20",
      "commands": [
        {
          "command": "wiki/log.md before",
          "outcome": "last ingest REQ-130; REQ-133..144 absent"
        },
        {
          "command": "prd_wiki_backfill.py --lint-links --fix",
          "outcome": "status ok, unlinked 0, fixed 1"
        },
        {
          "command": "index column-count check",
          "outcome": "rows with wrong column count: none"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1074 tests -- OK"
        },
        {
          "command": "prd_gate.py check / state_consistency_check.py",
          "outcome": "ok / ok"
        }
      ]
    },
    {
      "id": "EV-171",
      "type": "validation",
      "summary": "All three ai-collab-v3 reports resolved. REQ-148 (high): every Windows Codex hook dropped its `cmd /c \"if exist ...\"` wrapper, which allocates a console and flashed a window on every hook event - continuously, since PostToolUse fires per tool call. Replaced with a single python launch carrying an in-process os.path.isfile guard, so the REQ-029 guarantee (a missing dispatcher is a silent no-op, not an error) is preserved with no shell; a test executes the guard in an empty directory and asserts exit 0 with empty stderr. Corrected their diagnosis: the wrapper is not new in 0.16.39, it has shipped since 584e393 (~0.5.94). REQ-147: prd_install only added claude to the refresh list when --claude-skills was passed, so --force left .claude/skills stale while refreshing the other two host roots; an existing .claude/skills directory now counts as the earlier opt-in. REQ-146: their diagnosis was wrong - the invariant sentence was NEVER in the hub, it existed only as their own local edit under their REQ-140 and --force correctly overwrote it (verified by checking every commit that ever touched that file). The underlying ask was valid, so the invariant is now stated upstream and propagated to all mirrors, which fixes it permanently rather than per-update.",
      "linked_ids": [
        "REQ-146",
        "REQ-147",
        "REQ-148",
        "TRK-147"
      ],
      "created_at": "2026-07-20",
      "commands": [
        {
          "command": "python -m unittest tests.test_inbound_regressions (before)",
          "outcome": "FAILED: 36 failures, 4 errors"
        },
        {
          "command": "git log --all -S 'not sent until the configured upstream inbox'",
          "outcome": "only inside a requests.json message body from ai-collab-v3; never in the SKILL file"
        },
        {
          "command": "guard executed in an empty dir",
          "outcome": "returncode 0, stderr empty"
        },
        {
          "command": "python -m unittest tests.test_inbound_regressions",
          "outcome": "Ran 10 tests -- OK"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1084 tests -- OK"
        },
        {
          "command": "prd_gate.py check / state_consistency_check.py",
          "outcome": "ok / ok"
        }
      ]
    },
    {
      "id": "EV-172",
      "type": "validation",
      "summary": "0.16.40 published and registry-confirmed, host plugin refreshed 0.16.39 -> 0.16.40, and all three resolutions delivered to ai-collab-v3 with bodies verified on disk in their mailbox (1716, 822 and 2052 chars; 3 delivered, 0 pending, 0 undeliverable). Each reply states the fix, and the two corrections are stated plainly rather than buried: the cmd /c wrapper is not new in 0.16.39 but has shipped since ~0.5.94, and the missing invariant sentence was never in the hub at all. The Windows console behaviour is explicitly flagged as verified by their reproduction rather than mine, with an offer to re-diagnose if a window still appears.",
      "linked_ids": [
        "REQ-146",
        "REQ-147",
        "REQ-148",
        "TRK-147"
      ],
      "created_at": "2026-07-20",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1084 tests -- OK"
        },
        {
          "command": "python -m pytest system_tests -q",
          "outcome": "12 passed, 6 skipped"
        },
        {
          "command": "git push origin main && git push origin v0.16.40",
          "outcome": "5d389a0..e8fdc62 main -> main; [new tag] v0.16.40"
        },
        {
          "command": "publish_verify.py --version 0.16.40",
          "outcome": "published=true, latest_seen=0.16.40"
        },
        {
          "command": "claude plugin update",
          "outcome": "0.16.39 -> 0.16.40 for scope user"
        },
        {
          "command": "flush_pending_replies + mailbox read-back",
          "outcome": "delivered 3, pending 0; all three bodies verified present in their mailbox"
        }
      ]
    },
    {
      "id": "EV-173",
      "type": "validation",
      "summary": "REQ-149 implemented and verified. The plugin now ships hooks/hooks.json (and the skeleton copy), added to package.json files so it publishes. All five events are wired exec-form (no shell, no cmd /c console flash) addressing the dispatcher by ${CLAUDE_PLUGIN_ROOT}/.prd_plugin/hooks/prd_hook_dispatch.py with --source plugin. Double-fire is prevented: the dispatcher gained a --source arg and, on a plugin invocation, defers (silent exit 0) when the project's .claude/settings.json already wires PRD hooks. Verified end to end against real state: in THIS repo (which has settings hooks) the plugin invocation defers silently while the settings invocation still fires, and in a fresh repo with no settings hooks the plugin invocation fires the nudge. The dispatcher already resolves the project root from the hook payload cwd, so a script living in the plugin operates on the project's .prd_plugin, and it no-ops cleanly (exit 0) when a repo has no .prd_plugin. 9 new tests. NOT VERIFIED BY ME: that Claude Code Desktop actually loads hooks/hooks.json from the plugin - that rests on the documented plugin-hooks mechanism, since hooks already fire in my session via this repo's settings and I cannot reproduce the total-failure symptom from here.",
      "linked_ids": [
        "REQ-149",
        "TRK-148"
      ],
      "created_at": "2026-07-20",
      "commands": [
        {
          "command": "inspect installed 0.16.40 plugin cache",
          "outcome": "plugin.json has no hooks key; no hooks/hooks.json - zero plugin-native Claude hooks"
        },
        {
          "command": "python -m unittest tests.test_claude_plugin_hooks",
          "outcome": "Ran 9 tests -- OK"
        },
        {
          "command": "plugin-source dispatch in this repo (has settings hooks)",
          "outcome": "deferred: empty output, exit 0 - no double fire"
        },
        {
          "command": "plugin-source dispatch in a fresh repo (no settings hooks)",
          "outcome": "fired the nudge, exit 0"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1093 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-174",
      "type": "validation",
      "summary": "0.16.41 published and registry-confirmed, host plugin refreshed 0.16.40 -> 0.16.41. Verified the installed plugin now ships hooks/hooks.json with all five events, command `python ${CLAUDE_PLUGIN_ROOT}/.prd_plugin/hooks/prd_hook_dispatch.py`, and the dispatcher exists at that resolved path in the installed tree. The one remaining unknown is whether Claude Code Desktop's plugin loader executes it - that needs a Desktop restart and the user's observation, since hooks fire in my session via this repo's own settings and I cannot reproduce the total-failure symptom here.",
      "linked_ids": [
        "REQ-149",
        "TRK-148"
      ],
      "created_at": "2026-07-20",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1093 tests -- OK"
        },
        {
          "command": "git push origin main && git push origin v0.16.41",
          "outcome": "5cf7d22..5a91547 main -> main; [new tag] v0.16.41"
        },
        {
          "command": "publish_verify.py --version 0.16.41",
          "outcome": "published=true, latest_seen=0.16.41"
        },
        {
          "command": "claude plugin update",
          "outcome": "0.16.40 -> 0.16.41 for scope user"
        },
        {
          "command": "inspect installed 0.16.41 hooks/hooks.json",
          "outcome": "all 5 events present; dispatcher present at the CLAUDE_PLUGIN_ROOT path"
        }
      ]
    },
    {
      "id": "EV-175",
      "type": "validation",
      "summary": "REQ-150 implemented and verified. prd_stop_guard.decide() previously returned 'autonomy tier is not autonomous' for key_decision, so the guard was inert there. The tier gate is now a branch: autonomous keeps run-until-done; key_decision blocks an UNDECLARED stop while an open goal exists, with a message telling the agent to resolve the question itself and naming what does justify stopping (a real key decision, or the consent floor) plus the escape - write the question into .prd_plugin/local/autonomy-pause. guided is untouched and always allows a stop. The shared pause/goal/ownership/continue-cap logic is reused rather than duplicated. Gated by a new automation.key_decision_continue_guard toggle (default true, dependent on hooks.enabled + hooks.stop_guard.enabled), registered in the catalog so it is describable and switchable from the UI: 208 settings, 0 unknown, 0 invalid. 8 new tests; one pre-existing test that pinned the OLD behaviour was repurposed to guided rather than deleted. Guard copies re-synced across .claude/hooks, .prd_plugin/hooks and both skeletons (a mirror test caught one I missed).",
      "linked_ids": [
        "REQ-150",
        "TRK-149"
      ],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "read prd_stop_guard.decide()",
          "outcome": "line 173: `if auto.get('autonomy_level') != 'autonomous': return _stop(...)` - inert in key_decision"
        },
        {
          "command": "python -m unittest tests.test_stop_guard",
          "outcome": "Ran 41 tests -- OK (8 new)"
        },
        {
          "command": "prd_config.py describe automation.key_decision_continue_guard",
          "outcome": "resolves: bool, default true, runtime activation, depends on hooks.stop_guard.enabled"
        },
        {
          "command": "prd_config.py audit",
          "outcome": "208 settings, unclassified 0, unknown 0, invalid 0"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1101 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-176",
      "type": "validation",
      "summary": "0.16.42 published and registry-confirmed, host plugin refreshed 0.16.41 -> 0.16.42. Gates green before the tag (release_check, prd_gate, state_consistency all clean; 1101 tests OK at normal duration). The 3 errors seen on ~300s runs are the parked REQ-151 load sensitivity, confirmed three times: identical suites pass in isolation and the full suite passes at ~117s.",
      "linked_ids": [
        "REQ-150",
        "TRK-149"
      ],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1101 tests -- OK (117s)"
        },
        {
          "command": "git push origin main && git push origin v0.16.42",
          "outcome": "c33776e..1f125eb main -> main; [new tag] v0.16.42"
        },
        {
          "command": "publish_verify.py --version 0.16.42",
          "outcome": "published=true, latest_seen=0.16.42"
        },
        {
          "command": "claude plugin update",
          "outcome": "0.16.41 -> 0.16.42 for scope user"
        }
      ]
    },
    {
      "id": "EV-177",
      "type": "validation",
      "summary": "REQ-152 and REQ-153 implemented and verified. Worktree: confirmed safe before deleting - git status clean, no stashes, and 5b0ee29 is an ancestor of main so all history is preserved - then removed with git worktree remove. Two remaining hits were gitignored generated scratch from June 25: the traceability graph regenerated clean (1436 nodes, 5124 edges) and the stale cross-repo report was deleted. Canonical state (.prd_plugin/state, ids) never contained VectorSmith. A full repo sweep now returns zero references. Installer: config_diff and read_config_snapshot added, every install brackets config.json and reports config_changes as an ordered list of dotted keys with from/to, marking added/removed, with lists compared whole rather than elementwise so the output names settings not indices. Proven on a real install into a temp repo: the report listed each key the installer touched. Never raises - malformed input degrades to an empty list. 9 new tests.",
      "linked_ids": [
        "REQ-152",
        "REQ-153",
        "TRK-150"
      ],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "git grep -il vectorsmith",
          "outcome": "zero tracked references - removal had worked"
        },
        {
          "command": "git worktree list",
          "outcome": "found vigilant-mclean-9b8714 detached at 5b0ee29, pkg 0.5.86, 6.2 MB"
        },
        {
          "command": "git merge-base --is-ancestor 5b0ee29 main",
          "outcome": "true - no history lost by removing"
        },
        {
          "command": "git worktree remove + graph regen",
          "outcome": "repo-wide sweep: zero VectorSmith references"
        },
        {
          "command": "python -m unittest tests.test_install_config_diff",
          "outcome": "Ran 9 tests -- OK"
        },
        {
          "command": "real install into a temp repo",
          "outcome": "config_changes reported with from/to per key"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1110 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-178",
      "type": "validation",
      "summary": "0.16.43 published and registry-confirmed, host plugin refreshed to 0.16.43. Gates green before the tag: release_check and prd_gate clean, 1110 tests OK at normal duration (142s), 12 system tests passed / 6 skipped. The 3 errors on the 315s run are the parked REQ-151 load sensitivity, now seen on four separate releases.",
      "linked_ids": [
        "REQ-152",
        "REQ-153",
        "TRK-150"
      ],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1110 tests -- OK (142s)"
        },
        {
          "command": "python -m pytest system_tests -q",
          "outcome": "12 passed, 6 skipped"
        },
        {
          "command": "git push origin main && git push origin v0.16.43",
          "outcome": "70026dc..0412857 main -> main; [new tag] v0.16.43"
        },
        {
          "command": "publish_verify.py --version 0.16.43",
          "outcome": "published=true, latest_seen=0.16.43"
        }
      ]
    },
    {
      "id": "EV-179",
      "type": "validation",
      "summary": "Open-request reconciliation: six requests verified already implemented and closed, with the verification run today rather than inferred from status fields. REQ-107/REQ-117 (UTCP-first single canonical tool surface): the UTCP manual covers all 62 tools, exactly matching the tool-surface catalog's 49 MCP + 13 UTCP registrations across 18 capabilities, and test_utcp_first_catalog enforces the parity. REQ-116 (staleness_audit.py missing downstream): a real install into a temp repo delivers it - 31 scripts installed including staleness_audit.py - and it is registered downstream_runtime/installed_by_default in the scope manifest. REQ-118 (upstream acknowledgement and reconciliation loop): every component is present - apply_mailbox, reconcile_inbox, flush_pending_replies, prune_resolved_outbox, upstream_request_id stamping - and message_check reports unanswered_resolutions=0, pending_outbound_replies=0, outbox_packages=0. REQ-137/REQ-142 were outbound announcements to ai-collab-v3, not work items; both show delivery.state=delivered and both packages are present in their inbox.",
      "linked_ids": [
        "REQ-107",
        "REQ-116",
        "REQ-117",
        "REQ-118",
        "REQ-137",
        "REQ-142"
      ],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "prd_tools.build_static_manifest() vs templates/tool-surface.json",
          "outcome": "62 manual tools == 49 mcp + 13 utcp across 18 capabilities; parity guard test present"
        },
        {
          "command": "real prd_install into temp repo",
          "outcome": "staleness_audit.py delivered: True; 31 scripts installed"
        },
        {
          "command": "grep transport machinery + message_check",
          "outcome": "all 5 components present; totals 0 unanswered / 0 pending / 0 outbox"
        },
        {
          "command": "check REQ-137/REQ-142 delivery + peer inbox",
          "outcome": "both delivery=delivered; REQ-137.json and REQ-142.json present in ai-collab-v3 inbox"
        }
      ]
    },
    {
      "id": "EV-180",
      "type": "validation",
      "summary": "REQ-151 (Phase 1) implemented and verified under real load. Reproducing with CPU contention finally captured the actual failures, which had never been identified: 3 errors in test_claude_plugin_hooks.DeferralTests (subprocess timeout=60) and 1 FAILURE in test_reflections that was not load-related at all - it asserted the SHIPPED DEFAULT reflection.enabled=false against this repo's LIVE operator-owned config, which a /prd-on thorough had legitimately set true (the thorough profile sets exactly drift.monitoring.enabled, drift.monitoring.on_stop and reflection.enabled). Two defect classes, both making the suite red for non-code reasons. Fixes: (1) tests/support.py provides a shared HANG_TIMEOUT, generous by design because a timeout exists to catch a HANG, not to assert performance - a tight value conflates a busy machine with a stuck process; 9 tight timeouts across 6 files now use it, overridable via PRD_TEST_HANG_TIMEOUT. (2) three tests stopped pinning the VALUES of live operator-owned config and now assert shape only, keeping value assertions on the shipped templates where they belong - two of those (agent_artifact_readability_policy, claude_adapter) were latent instances found by the new guard, on keys confirmed operator-mutable in the catalog. A new test_suite_load_tolerance pins both rules. My first guard regex was too broad - it matched templates/repo-skeleton/.prd_plugin/config.json and temp-dir Path joins - and was narrowed rather than trusted.",
      "linked_ids": [
        "REQ-151",
        "TRK-151"
      ],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "full suite under 8 CPU burners (before)",
          "outcome": "FAILED: 3 errors in DeferralTests + 1 failure in test_reflections"
        },
        {
          "command": "previously-failing suites under the SAME 8-core load (after)",
          "outcome": "Ran 82 tests in 345.293s -- OK"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1114 tests -- OK"
        },
        {
          "command": "prd_gate.py check / state_consistency_check.py",
          "outcome": "ok / ok"
        }
      ]
    },
    {
      "id": "EV-181",
      "type": "validation",
      "summary": "REQ-145 (Phase 2) implemented. scripts/wiki_ingest_drift.py reports implemented requests with no corresponding wiki ingest, surfaced through prd_status only when there is drift so a clean repo stays quiet. The anchoring was the design crux and I got it wrong first: anchoring on the EARLIEST cited request surfaced ~70 historical items in this repo and buried the signal, so it now anchors on the wiki's HIGH-WATER MARK - the actionable question is 'what shipped since the last ingest'. Older gaps are counted as historical_gap for transparency rather than hidden. Against real state it reports exactly the 12 uningested requests REQ-141..REQ-153 with baseline REQ-140 and historical_gap 60, matching the gap found by hand. Fails safe: a repo with no wiki reports no_wiki rather than drift, non-implemented requests are never expected in the log, and malformed state degrades instead of raising. I also fixed a test of my own that pinned a specific missing id - it would have failed the moment the wiki was ingested, punishing the fix - and it now asserts shape plus that every reported id is a real implemented request.",
      "linked_ids": [
        "REQ-145",
        "TRK-151"
      ],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "python -m unittest tests.test_wiki_ingest_drift",
          "outcome": "Ran 9 tests -- OK"
        },
        {
          "command": "wiki_ingest_drift.py --repo-root . (first anchoring)",
          "outcome": "~70 items from REQ-055 onward - signal buried, anchoring rejected"
        },
        {
          "command": "wiki_ingest_drift.py --repo-root . (high-water anchoring)",
          "outcome": "12 uningested REQ-141..153, baseline REQ-140, historical_gap 60"
        }
      ]
    },
    {
      "id": "EV-182",
      "type": "validation",
      "summary": "REQ-107 Phase 3 (authority inversion) implemented and verified. templates/tool-spec.json is the authored source for all 62 tools; mcp/server.cjs reads it for definitions and contributes only handlers; build_manual generates from it; tool-metadata.json is a derived projection checked against the spec. The installer delivers the spec so a downstream server cannot drift from its manual (verified by a real install: 62 tools delivered). Execution untouched by design - the write path migrates tool by tool, and the target pattern is already proven because prd_reflections.py mutates canonical state under the SAME mcp-state.lock as the server. The official @utcp/mcp-bridge 1.1.0 was run against our manual and responded, but it exposes a 7 meta-tool facade rather than proxying named tools, so per DEC-014 it ships as a supported config instead of the downstream default. HONEST LIMIT: one REQ-107 clause - downstream .mcp.json pointing at the bridge - is deliberately NOT met, because it would collapse 62 named tools into 7 and break every skill that names one. The remaining migration (32 JS handlers to native cli entry points) is real outstanding work.",
      "linked_ids": [
        "REQ-107",
        "DEC-014",
        "TRK-151"
      ],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "generate templates/tool-spec.json from the live server + catalog",
          "outcome": "62 tools (49 mcp, 13 cli), 0 uncataloged"
        },
        {
          "command": "python -m unittest tests.test_utcp_first_authority",
          "outcome": "Ran 8 tests -- OK"
        },
        {
          "command": "real install into a temp repo",
          "outcome": ".prd_plugin/templates/tool-spec.json delivered with 62 tools"
        },
        {
          "command": "@utcp/mcp-bridge 1.1.0 mounted against utcp.json",
          "outcome": "bridge responded; serves 7 meta-tools (search_tools/call_tool/...), not 62 named tools"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1131 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-183",
      "type": "validation",
      "summary": "CORRECTION to EV-180 (REQ-151). That evidence attributed the three recurring DeferralTests errors to hard-coded subprocess timeouts under CPU load. That was WRONG, and the timeout change made them worse rather than better. The real cause, found when they recurred at HANG_TIMEOUT=300: prd_hook_dispatch reads its hook payload from sys.stdin, and the test invoked it via subprocess.run WITHOUT input=, so the child inherited a still-open stdin and blocked FOREVER. An interactive shell already has stdin at EOF, which is why it passed in isolation and under a deliberate load test; a background full-suite run inherits an open stdin, which is why it failed there. Raising the timeout 60s -> 300s turned three infinite blocks into three 300s waits - about 900s of the 1317s run. Fixed by passing input='' for an explicit EOF, and guarded by a new test asserting every dispatcher invocation closes stdin. The HANG_TIMEOUT work stands on its own merits (a timeout catches a hang, it does not assert performance) and the operator-config half of EV-180 was correct, but the DeferralTests attribution was not. My own circuit-breaker rule applied: second find in the same subsystem, so I re-grounded instead of patching again.",
      "linked_ids": [
        "REQ-151",
        "EV-180"
      ],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "read the actual TimeoutExpired traceback",
          "outcome": "dispatcher timed out after 300s - an infinite block, not slowness"
        },
        {
          "command": "subprocess.run(dispatcher) with inherited stdin vs input=''",
          "outcome": "inherited stdin can hang; input='' exits 0 immediately"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1142 tests -- OK (415s, down from 1317s)"
        }
      ]
    },
    {
      "id": "EV-184",
      "type": "validation",
      "summary": "REQ-113 (Phase 4) implemented and verified. scripts/request_thread.py closes a finished request thread with a required reason and timestamp, under the same .prd_plugin/local/mcp-state.lock as every other canonical mutation, so it is safe alongside the MCP server. Built the REQ-107 way: declared once in templates/tool-spec.json and the tool-surface catalog, with the server contributing only a handler. Guardrails: a reason is required because an unexplained close is unauditable; only a settled request (implemented/rejected/deferred) may have its thread closed, so live work is never hidden; closing is idempotent; and a refusal never writes. Proven on real state - the four genuinely stale threads on implemented requests (REQ-135, 146, 147, 148) closed and message_check went from 5 unresolved to 1, with REQ-129 correctly left alone because it is still in_review.",
      "linked_ids": [
        "REQ-113",
        "REQ-107",
        "TRK-151"
      ],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "python -m unittest tests.test_thread_close",
          "outcome": "Ran 10 tests -- OK"
        },
        {
          "command": "close the 4 stale threads on real state",
          "outcome": "unresolved_threads 5 -> 1 (REQ-129 left open, still in_review)"
        },
        {
          "command": "python -m unittest discover -s tests",
          "outcome": "Ran 1142 tests -- OK"
        }
      ]
    },
    {
      "id": "EV-185",
      "type": "measurement",
      "summary": "Control surface verified in-browser at 375/768/1280px, light and dark; one real responsive defect found and fixed",
      "linked_ids": [],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "python scripts/prd_ui_serve.py --repo-root <sandbox> --port 8793",
          "outcome": "200 on /, config POSTs wrote through to the sandbox config.json"
        },
        {
          "command": "python -m unittest tests.test_prd_ui_export -q",
          "outcome": "Ran 17 tests - OK (includes the new narrow-viewport guard)"
        }
      ],
      "limitations": "The browser pane's screenshot action timed out repeatedly, so this is measured rather than eyeballed. DOM interaction, navigation and layout measurement all worked; only raster capture failed."
    },
    {
      "id": "EV-186",
      "type": "validation",
      "summary": "REQ-154: denied-mkdir contention fixed in all three lock implementations",
      "linked_ids": [],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "node --test tests/node/server.test.cjs",
          "outcome": "60 pass / 0 fail (was 59 pass / 1 fail on the concurrency test)"
        },
        {
          "command": "python -m unittest tests.test_thread_close tests.test_reflections -q",
          "outcome": "11 OK and 16 OK"
        }
      ]
    },
    {
      "id": "EV-187",
      "type": "validation",
      "summary": "prd-plugin@0.16.44 confirmed on the npm registry by read-back",
      "linked_ids": [],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "git push origin main && git push origin v0.16.44",
          "outcome": "ca3cb3a..c02e432 main -> main; [new tag] v0.16.44"
        },
        {
          "command": "python scripts/publish_verify.py --version 0.16.44",
          "outcome": "published: true, version_seen 0.16.44, latest_seen 0.16.44, attempts_used 1"
        }
      ]
    },
    {
      "id": "EV-188",
      "type": "validation",
      "summary": "REQ-155: a repo's own Codex hooks now survive a forced plugin refresh",
      "linked_ids": [],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "python -m unittest tests.test_prd_install -q",
          "outcome": "Ran 90 tests - OK (5 new)"
        }
      ]
    },
    {
      "id": "EV-189",
      "type": "review",
      "summary": "REQ-156: the reply-delivery invariant was present all along - a line break inside the sentence defeated the check",
      "linked_ids": [],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "grep -c 'is not sent until the configured upstream inbox' skills/project-request-intake/SKILL.md",
          "outcome": "1 (was 0 for the wrapped form; the text itself never changed)"
        }
      ]
    },
    {
      "id": "EV-190",
      "type": "validation",
      "summary": "prd-plugin@0.16.45 confirmed on the npm registry and refreshed on all three channels",
      "linked_ids": [
        "REQ-155",
        "REQ-156"
      ],
      "created_at": "2026-07-21",
      "commands": [
        {
          "command": "python scripts/publish_verify.py --version 0.16.45",
          "outcome": "published: true, version_seen 0.16.45, latest_seen 0.16.45"
        },
        {
          "command": "claude plugin update prd-plugin@prd-plugin",
          "outcome": "updated from 0.16.44 to 0.16.45 for scope user"
        }
      ]
    },
    {
      "id": "EV-191",
      "type": "validation",
      "summary": "REQ-158: Codex hook ownership is now per entry, so a repo hook sharing a group with ours survives",
      "linked_ids": [],
      "created_at": "2026-07-22",
      "commands": [
        {
          "command": "python -m unittest tests.test_prd_install -q",
          "outcome": "Ran 93 tests - OK (3 new; the mixed-group one failed before the fix)"
        }
      ]
    },
    {
      "id": "EV-192",
      "type": "validation",
      "summary": "REQ-159: mojibake removed from shipped tool metadata, and the mechanism that caused it fixed",
      "linked_ids": [],
      "created_at": "2026-07-22",
      "commands": [
        {
          "command": "python -m unittest tests.test_utcp_first_authority -q",
          "outcome": "Ran 12 tests - OK (4 new; 2 failed before the fix)"
        },
        {
          "command": "python -m unittest discover -s tests -q",
          "outcome": "Ran 1160 tests - OK"
        }
      ]
    },
    {
      "id": "EV-193",
      "type": "validation",
      "summary": "REQ-160: a PreToolUse guard now enforces full-tests-before-commits-only, scoped everywhere else",
      "linked_ids": [],
      "created_at": "2026-07-22",
      "commands": [
        {
          "command": "python -m unittest tests.test_test_scope_guard -q",
          "outcome": "Ran 20 tests - OK"
        },
        {
          "command": "python -m unittest tests.test_prd_install tests.test_config_toggles tests.test_test_scope_guard -q",
          "outcome": "Ran 134 tests - OK"
        }
      ]
    },
    {
      "id": "EV-194",
      "type": "measurement",
      "summary": "REQ-161: three shadowed tests found, lost assertions recovered, guard added",
      "linked_ids": [],
      "created_at": "2026-07-22",
      "commands": [
        {
          "command": "python -m unittest tests.test_no_shadowed_tests",
          "outcome": "failed naming 3 shadowed definitions; green after the fix"
        },
        {
          "command": "python -m unittest tests.test_no_shadowed_tests tests.test_prd_install tests.test_test_scope_guard -q",
          "outcome": "Ran 114 tests - OK"
        }
      ]
    },
    {
      "id": "EV-195",
      "type": "validation",
      "summary": "REQ-163: instruction-file rule parity is now validated, and test-first is an always-in-force rule in all four files",
      "linked_ids": [],
      "created_at": "2026-07-22",
      "commands": [
        {
          "command": "python scripts/instruction_parity.py",
          "outcome": "4 findings before the fix (2 demotion, 2 missing); status ok after"
        },
        {
          "command": "python -m unittest tests.test_instruction_parity tests.test_workflow_chml_audit tests.test_prd_install -q",
          "outcome": "Ran 102 tests - OK"
        }
      ]
    },
    {
      "id": "EV-196",
      "type": "validation",
      "summary": "prd-plugin@0.16.46 confirmed on the npm registry and refreshed on all three channels",
      "linked_ids": [
        "REQ-158",
        "REQ-159",
        "REQ-160",
        "REQ-161",
        "REQ-163"
      ],
      "created_at": "2026-07-22",
      "commands": [
        {
          "command": "git push origin main && git push origin v0.16.46",
          "outcome": "c81fd90..a6562a2 main -> main; [new tag] v0.16.46"
        },
        {
          "command": "python scripts/publish_verify.py --version 0.16.46",
          "outcome": "published true, version_seen 0.16.46, attempts_used 1"
        },
        {
          "command": "claude plugin update prd-plugin@prd-plugin",
          "outcome": "updated 0.16.45 -> 0.16.46 for scope user"
        }
      ]
    },
    {
      "id": "EV-197",
      "type": "validation",
      "summary": "Windows-safe verification execution and deterministic full-suite guard fixture verified green for 0.16.47.",
      "linked_ids": [
        "REQ-166",
        "TRK-152"
      ],
      "created_at": "2026-07-23",
      "commands": [
        {
          "command": "python -m unittest tests.test_test_scope_execution -q",
          "outcome": "4 tests passed after the failing regression proved bare npm was not resolved."
        },
        {
          "command": "python -m unittest tests.test_test_scope tests.test_test_scope_execution tests.test_prd_workflows -q",
          "outcome": "28 tests passed."
        },
        {
          "command": "python -m unittest tests.test_test_scope_guard -q",
          "outcome": "23 tests passed after isolating the live-Git-dependent fixture."
        },
        {
          "command": "python scripts/prd_test_scope.py --repo-root . --execute",
          "outcome": "Full strategy passed; npm test exit 0; 1,192 tests passed in 414.160 seconds."
        },
        {
          "command": "python -m unittest tests.test_release_check tests.test_gap_audit tests.test_skills_manifest tests.test_local_workflow_check tests.test_prd_install -q",
          "outcome": "125 focused release and installer tests passed."
        },
        {
          "command": "python scripts/local_workflow_check.py --target-version 0.16.47 --skip-tests",
          "outcome": "Structured validation, feature-skill audit, gap audit, release hygiene, doctor, state consistency, installer dry-run, requests and messages completed."
        }
      ],
      "limitations": "AI-Collab/Substrate is configured off, so impact-scoped execution correctly widened to the local full suite. No remote push, tag, npm publication, or downstream repository mutation was performed."
    },
    {
      "id": "EV-198",
      "type": "validation",
      "summary": "Final REQ-166 verification execution path passed full deterministic workflow and source-bound review for 0.16.47.",
      "linked_ids": [
        "REQ-166",
        "TRK-152",
        "CHG-127"
      ],
      "created_at": "2026-07-23",
      "commands": [
        {
          "command": "node --test --test-name-pattern=workflow bridge timeout tests/node/server.test.cjs",
          "outcome": "Regression failed before the bridge implementation, then passed after the bridge budget followed configured verification bounds."
        },
        {
          "command": "node --test tests/node/server.test.cjs",
          "outcome": "61 MCP server tests passed after the multi-command timeout refinement."
        },
        {
          "command": "engineering.verify WFR-377",
          "outcome": "Completed in 412.6 seconds: full npm test passed with 1,193 tests; diff check, state consistency, and state gate all passed with zero findings."
        },
        {
          "command": "engineering.code-review WFR-379",
          "outcome": "Final hash-bound review completed with no remaining material findings."
        }
      ],
      "limitations": "Substrate is configured off, so verification used the deterministic local full-suite fallback. No push, tag, npm publication, or downstream repository mutation was performed."
    },
    {
      "id": "EV-199",
      "type": "validation",
      "summary": "CRAFTESB is a complete near-top core-philosophy section in hub and downstream AGENTS.md/CLAUDE.md; regression and installer coverage pass, the full 1,194-test suite passes, and repository state and completion gates report zero findings.",
      "linked_ids": [
        "REQ-167",
        "TRK-153"
      ],
      "created_at": "2026-07-23",
      "commands": [
        {
          "command": "python -m unittest tests.test_instruction_parity.CraftesbIsCorePhilosophyTests -v",
          "outcome": "RED before implementation: missing prominent CRAFTESB section; PASS after implementation."
        },
        {
          "command": "python -m unittest tests.test_prd_install.PrdInstallTests.test_force_overwrites_existing_plugin_files -v",
          "outcome": "PASS: force refresh replaces stale AGENTS.md and CLAUDE.md with complete CRAFTESB content."
        },
        {
          "command": "python -m unittest tests.test_instruction_parity tests.test_decision_policy tests.test_grounding_estimation tests.test_claude_nudge tests.test_prd_skill_install tests.test_prd_install.PrdInstallTests.test_force_overwrites_existing_plugin_files -q",
          "outcome": "PASS: 73 scoped tests."
        },
        {
          "command": "engineering.verify WFR-385",
          "outcome": "PASS: npm test ran 1,194 tests; state consistency and state gate both returned zero findings."
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.16.48",
          "outcome": "PASS: no gaps."
        },
        {
          "command": "python scripts/release_check.py",
          "outcome": "PASS: no findings."
        },
        {
          "command": "python scripts/instruction_parity.py --repo-root .",
          "outcome": "PASS: instruction parity is current."
        },
        {
          "command": "python scripts/generate_skills_manifest.py --check",
          "outcome": "PASS: 44-skill manifest current."
        },
        {
          "command": "python scripts/feature_skill_audit.py --repo-root . --format json",
          "outcome": "PASS: all 28 features have zero CHML findings."
        }
      ],
      "limitations": "The downstream consumer repository was inspected read-only. This hub release prepares corrected templates; updating any separate repository remains a distinct authorized operation."
    },
    {
      "id": "EV-200",
      "type": "validation",
      "summary": "Autonomous git workflow now requires pushing a clean verified commit without redundant finish options across all seven host-discovery copies; regression, policy, wiki, release, full-suite, state, and gate checks pass.",
      "linked_ids": [
        "REQ-168",
        "TRK-154"
      ],
      "created_at": "2026-07-23",
      "commands": [
        {
          "command": "targeted autonomous-push regression",
          "outcome": "RED against all stale skill copies before implementation; PASS after all seven copies were updated."
        },
        {
          "command": "python -m unittest tests.test_workflow_consistency tests.test_prd_skill_install tests.test_release_publication_policy tests.test_decision_policy -q",
          "outcome": "PASS: 49 tests."
        },
        {
          "command": "engineering.verify WFR-390",
          "outcome": "PASS: full npm test suite ran 1,194 tests; state consistency and state gate returned zero findings."
        },
        {
          "command": "python -m unittest tests.test_workflow_consistency tests.test_prd_skill_install tests.test_release_publication_policy tests.test_decision_policy tests.test_llm_wiki tests.test_wiki_backfill tests.test_wiki_page_contract -q",
          "outcome": "PASS: 106 scoped policy, skill-delivery, and wiki tests."
        },
        {
          "command": "python scripts/prd_wiki_backfill.py --lint-links --fix --format json",
          "outcome": "PASS: zero unlinked or fixed findings."
        },
        {
          "command": "python scripts/gap_audit.py --target-version 0.16.49",
          "outcome": "PASS: no findings."
        },
        {
          "command": "python scripts/release_check.py",
          "outcome": "PASS: no findings."
        }
      ],
      "limitations": "Normal autonomous push and merge are tier-governed; force-push, secrets, cross-repository edits, and other hard-floor actions still require explicit authority."
    },
    {
      "id": "EV-201",
      "type": "validation",
      "summary": "Human-readable UI rule verified across all four agent instruction files, both reporting-method copies, installer delivery, release metadata, and the complete repository gate; hub.release WFR-392 completed with 1,194 tests passing and all workflow, Substrate, state, release, gap, package, and final gate checks green.",
      "linked_ids": [
        "REQ-169",
        "TRK-155",
        "CHG-130",
        "WFR-392"
      ],
      "created_at": "2026-07-24",
      "commands": [
        {
          "command": "python -m unittest tests.test_grounding_estimation tests.test_method_docs tests.test_instruction_parity tests.test_release_check tests.test_prd_install -v",
          "outcome": "140 focused instruction, parity, release, and installer tests passed."
        },
        {
          "command": "prd_workflow_run hub.release (WFR-392)",
          "outcome": "Completed; 1,194 tests passed in the suite step; workflow/CHML, Substrate, config, state, release, gap, package, and final gate checks passed."
        }
      ],
      "limitations": "The rule governs agent-authored or agent-reviewed UI work; it does not retroactively rewrite existing product interfaces in downstream repositories."
    },
    {
      "id": "EV-202",
      "type": "validation",
      "summary": "Verified the settings decision UI: 109 settings render once in 11 semantic collapsed groups; 12 high-impact settings explain use cases, on/off effects, and bounded or environment-dependent latency; browser checks passed at desktop and 420px widths; both deterministic verification and the hub release gate completed with 1,199 tests passing, release metadata clean, gap audit clean, and the 0.16.51 package containing 639 files.",
      "linked_ids": [
        "REQ-170",
        "TRK-156",
        "WFR-395",
        "WFR-396",
        "WFR-397"
      ],
      "created_at": "2026-07-24",
      "commands": [
        {
          "command": "python -m unittest tests.test_prd_ui_export tests.test_prd_ui_serve -v",
          "outcome": "36 tests passed"
        },
        {
          "command": "in-app browser inspection of loopback PRD UI",
          "outcome": "11 collapsed groups, 109 settings, 12 guidance disclosures, readable accessible names, no horizontal overflow at 420px"
        },
        {
          "command": "engineering.code-review WFR-395",
          "outcome": "completed with no material findings"
        },
        {
          "command": "engineering.verify WFR-396",
          "outcome": "completed; 1,199 tests passed; zero state errors or warnings"
        },
        {
          "command": "hub.release WFR-397",
          "outcome": "all 10 release steps completed; 1,199 tests passed; release, gap, package, and final gates green"
        }
      ],
      "limitations": "Portable latency measurements are not claimed: exact timings vary by repository, runtime, and enabled subfeatures; the UI quotes configured timeout bounds where available and labels other costs as environment-dependent."
    },
    {
      "id": "EV-203",
      "type": "validation",
      "summary": "Reasoning Guard 0.16.52 verified across shared engine, Claude/Codex/OpenCode wiring, installer upgrades, configuration UI/status, local state security, lifecycle reconciliation, and release packaging.",
      "linked_ids": [
        "REQ-171",
        "TRK-157",
        "HLT-024",
        "WFR-400",
        "WFR-402",
        "WFR-404"
      ],
      "created_at": "2026-07-24",
      "commands": [
        {
          "command": "python -m unittest discover -s tests -v",
          "outcome": "1235 tests passed in the final hub-release workflow."
        },
        {
          "command": "python -m pytest system_tests -v",
          "outcome": "12 scenarios passed; 6 optional live-OpenCode scenarios skipped by the harness."
        },
        {
          "command": "python scripts/local_workflow_check.py --repo-root . --target-version 0.16.52 --include-system-tests",
          "outcome": "Completed with unit, system, instruction parity, feature-skill, state, report, and structured-file checks green."
        },
        {
          "command": "engineering.code-review workflow",
          "outcome": "Hash-bound review completed after audit/fix loop with no remaining material findings."
        },
        {
          "command": "hub.release workflow",
          "outcome": "All 10 deterministic release-boundary steps completed, including release/gap/package/gate checks."
        },
        {
          "command": "npm pack --dry-run --json",
          "outcome": "0.16.52 package includes the live and downstream guard engines, operator guide, and downstream AGENTS.md/CLAUDE.md."
        }
      ],
      "limitations": "Six opt-in system scenarios that require a live OpenCode executable were skipped; OpenCode event wiring, blocking/reprompt behavior, parity, and installed dispatcher behavior are covered by deterministic integration tests."
    },
    {
      "id": "EV-204",
      "type": "validation",
      "summary": "Verified the Codex Reasoning Guard coverage correction end to end: official rollout-shaped visible summaries are extracted through the real dispatcher, private/encrypted reasoning is excluded, session coverage accumulates and resets correctly, and malformed legacy coverage recovers without crashing.",
      "linked_ids": [
        "REQ-172",
        "REQ-171",
        "TRK-158",
        "CHG-134"
      ],
      "created_at": "2026-07-24",
      "commands": [
        {
          "command": "python -m unittest tests.test_reason_guard -q (RED)",
          "outcome": "Failed on missing Codex summary extraction and overwritten cumulative coverage, proving the regressions."
        },
        {
          "command": "python -m unittest tests.test_reason_guard tests.test_hook_dispatcher tests.test_cross_host_hook_parity -q",
          "outcome": "61 tests passed, including the real subprocess dispatcher-to-rollout-to-report path and privacy sentinels."
        },
        {
          "command": "python scripts/local_workflow_check.py --target-version 0.16.53 --include-system-tests",
          "outcome": "1,241 unit tests passed; 12 system tests passed and 6 optional OpenCode scenarios skipped; structured validation, release hygiene, and local workflow checks passed."
        },
        {
          "command": "python scripts/workflow_chml_audit.py; python scripts/prd_services.py audit; python scripts/prd_substrate_catalog.py audit",
          "outcome": "All three audits returned status ok with critical/high/medium/low counts all zero."
        },
        {
          "command": "python scripts/state_consistency_check.py --repo-root . --format json; python scripts/gap_audit.py --target-version 0.16.53 --no-fail",
          "outcome": "Canonical state passed with no errors or warnings; release gap audit reported no findings."
        }
      ],
      "limitations": "Optional live OpenCode system scenarios were skipped by the existing mock-driven system-test policy. Pre-existing wiki staleness warnings outside the Reasoning Guard article remain bounded out of this fix; workflow CHML is zero and REQ-172 has no wiki-ingest gap."
    },
    {
      "id": "EV-205",
      "type": "validation",
      "summary": "Structured Reasoning Diagnostic kernel verified across bounded directives, schema migration, typed evidence, coalesced diagnostics, coverage-qualified clearance, Claude/Codex/OpenCode parity, downstream install, latency, privacy, and release surfaces.",
      "linked_ids": [
        "REQ-173",
        "TRK-159",
        "PRD-011",
        "ARCH-011",
        "IMP-013",
        "HLT-025",
        "WFR-411",
        "WFR-413"
      ],
      "created_at": "2026-07-24",
      "commands": [
        {
          "command": "npm test",
          "outcome": "1259 tests passed"
        },
        {
          "command": "engineering.verify",
          "outcome": "WFR-413 completed; state and gate passed"
        },
        {
          "command": "reason_guard_benchmark.py --samples 100",
          "outcome": "structured p95 21.478 ms; delta p95 5.445 ms; budgets passed"
        },
        {
          "command": "service, substrate, workflow, and feature audits",
          "outcome": "critical 0, high 0, medium 0, low 0"
        },
        {
          "command": "prd_self_audit.py",
          "outcome": "zero findings after canonical risk linkage"
        },
        {
          "command": "release_check.py and gap_audit.py --target-version 0.16.54",
          "outcome": "no findings"
        }
      ],
      "limitations": "RSP and standalone-server work were explicitly excluded. The kernel operates only on host-visible summaries/events and reports reduced or missing coverage honestly. No downstream repository was modified as part of this hub release."
    },
    {
      "id": "EV-206",
      "type": "validation",
      "summary": "Canonical hub release workflow completed for PRD Plugin 0.16.54: full local workflow check, release hygiene, gap audit, package dry run, config/state gates, and workflow/Substrate CHML audits all passed.",
      "linked_ids": [
        "REQ-173",
        "TRK-159",
        "PRD-011",
        "ARCH-011",
        "IMP-013",
        "HLT-025",
        "WFR-414"
      ],
      "created_at": "2026-07-24",
      "commands": [
        {
          "command": "hub.release",
          "outcome": "WFR-414 completed all ten steps"
        },
        {
          "command": "local_workflow_check.py",
          "outcome": "1259 tests and structured validation passed"
        },
        {
          "command": "npm pack --dry-run",
          "outcome": "prd-plugin 0.16.54 package check passed; 649 files"
        }
      ],
      "limitations": "Publication occurs only after the verified commit is merged to main and the annotated v0.16.54 tag is pushed."
    },
    {
      "id": "EV-207",
      "type": "validation",
      "summary": "Codex session-ID rollout fallback passes regression, privacy, ambiguity, installer, full-suite, state, and latency verification.",
      "linked_ids": [
        "REQ-172",
        "TRK-160"
      ],
      "created_at": "2026-07-25",
      "commands": [
        {
          "command": "python -m unittest tests.test_reason_guard -q",
          "outcome": "49 tests passed"
        },
        {
          "command": "python -m unittest tests.test_reason_guard tests.test_prd_install -q",
          "outcome": "144 tests passed"
        },
        {
          "command": "engineering.verify release=true",
          "outcome": "WFR-416 completed; npm test passed 1262 tests; state consistency 0 errors and 0 warnings; gate had no actionable finding"
        },
        {
          "command": "real AI-Collab-v3 rollout benchmark",
          "outcome": "direct path p95 15.676 ms; session fallback p95 27.522 ms across a 297-session store; both below 50 ms budget"
        }
      ],
      "limitations": "Live Codex hook payloads are not persisted verbatim for privacy. Root cause is discriminated from structural rollout metadata, report timing, official hook nullability, and direct parser behavior; downstream live verification remains part of the release goal."
    },
    {
      "id": "EV-208",
      "type": "review",
      "summary": "Self-review found no critical, important, or minor defects in the trusted rollout fallback diff.",
      "linked_ids": [
        "REQ-172",
        "TRK-160",
        "EV-207"
      ],
      "created_at": "2026-07-25",
      "commands": [
        {
          "command": "git diff --cached -- implementation, tests, docs, and wiki",
          "outcome": "Reviewed requirements alignment, trust boundary, fail-closed ambiguity handling, compatibility, and test coverage; no findings"
        },
        {
          "command": "git diff --no-index -- hub hook template hook",
          "outcome": "Exact source/template parity"
        }
      ],
      "limitations": "Review was performed by the implementing agent because the user did not authorize subagents."
    },
    {
      "id": "EV-209",
      "type": "validation",
      "summary": "The 0.16.55 hub release boundary is green across workflow CHML, Substrate capability parity, full tests, package contents, release hygiene, gap audit, and state gate.",
      "linked_ids": [
        "REQ-172",
        "TRK-160",
        "CHG-136",
        "EV-207",
        "EV-208"
      ],
      "created_at": "2026-07-25",
      "commands": [
        {
          "command": "hub.release",
          "outcome": "WFR-417 completed"
        },
        {
          "command": "workflow_chml_audit",
          "outcome": "critical 0, high 0, medium 0, low 0"
        },
        {
          "command": "prd_substrate_catalog audit",
          "outcome": "26 capabilities, 103 runtime tools, 31 intents, no findings"
        },
        {
          "command": "local_workflow_check",
          "outcome": "passed including 1262-test full suite"
        },
        {
          "command": "release_check and gap_audit",
          "outcome": "passed with no release gap"
        },
        {
          "command": "npm pack --dry-run",
          "outcome": "prd-plugin 0.16.55 package built with 649 files"
        }
      ],
      "limitations": "Remote main, tag publication, and downstream AI-Collab-v3 live verification follow this local release-boundary receipt."
    },
    {
      "id": "EV-210",
      "type": "validation",
      "summary": "Reason Guard semantic-lite classification, conditional clearance, aggregate telemetry, status/UI projection, and downstream template parity verified against labelled replay, full hub release gates, and mock-driven system scenarios.",
      "linked_ids": [
        "REQ-174",
        "TRK-161",
        "IMP-014",
        "IMP-TASK-113",
        "IMP-TASK-114",
        "WFR-420",
        "WFR-421",
        "WFR-422"
      ],
      "created_at": "2026-07-25",
      "commands": [
        {
          "command": "python scripts/reason_guard_benchmark.py --samples 100 --warmup 10 --json",
          "outcome": "44/44 labelled cases correct; precision, recall, F1, and accuracy 1.0; classifier p95 0.013 ms; structured hook p95 18.684 ms; delta 4.515 ms."
        },
        {
          "command": "python scripts/prd_workflows.py --repo-root . run hub.release --idempotency-key codex-reason-guard-semantic-lite-release-v1 --json",
          "outcome": "Completed; CHML critical/high/medium/low all 0; full unit suite and release/package gates passed."
        },
        {
          "command": "python -m pytest system_tests -v",
          "outcome": "12 passed; 6 optional OpenCode live-driver scenarios skipped."
        }
      ],
      "limitations": "Accuracy is established on the checked-in 44-case balanced and adversarial corpus; runtime aggregate counters support measuring future observed traffic without retaining extra text."
    },
    {
      "id": "EV-211",
      "type": "validation",
      "summary": "Live PRD Plugin Codex session verification proved transcript fallback, Markdown active-heading classification, conditional clearance, accuracy/latency budgets, downstream parity, full release gates, and system scenarios.",
      "linked_ids": [
        "REQ-174",
        "TRK-161",
        "IMP-014",
        "EV-210",
        "WFR-425",
        "WFR-426",
        "WFR-427",
        "WFR-428"
      ],
      "created_at": "2026-07-25",
      "commands": [
        {
          "command": "Live Codex PreToolUse event with session_id 019f8f2a-71a4-7920-94a0-66cf3307c73b and no reasoning_summary",
          "outcome": "Trusted transcript fallback reached full Codex coverage and incremented observed-summary telemetry; neutral current summaries were correctly ignored."
        },
        {
          "command": "Replay exact visible candidate from the same 548-summary session through prd_reason_guard.py",
          "outcome": "Session contained 3 qualifying candidates; replay created 1 low-confidence obligation, open became 1, and clearance changed from clear to conditional."
        },
        {
          "command": "python scripts/reason_guard_benchmark.py --samples 100 --warmup 10 --json",
          "outcome": "46/46 labelled cases correct; precision, recall, F1, accuracy 1.0; classifier p95 0.011 ms; structured hook p95 18.812 ms; delta 3.776 ms."
        },
        {
          "command": "python scripts/prd_workflows.py --repo-root . run hub.release --idempotency-key codex-reason-guard-markdown-release-v1 --json",
          "outcome": "Completed; full unit suite, CHML 0/0/0/0, state, release, gap, package, and capability gates passed."
        },
        {
          "command": "python -m pytest system_tests -v",
          "outcome": "12 passed; 6 optional OpenCode live-driver scenarios skipped."
        }
      ],
      "limitations": "Transcript fallback was exercised directly on the live current session. Because its newest generated headings were neutral and correctly ignored, the positive path replayed an exact visible candidate from the same session through the full hook/report/status path rather than waiting for the formatter to emit that wording again."
    },
    {
      "id": "EV-212",
      "type": "validation",
      "summary": "Confidence-bounded Reason Guard abstention verified against the active PRD Plugin Codex session, a frozen real-session holdout, focused tests, full hub release gates, and system scenarios. The holdout had zero false obligations and misses, 1.0 safety recall, 0.7778 overall clear specificity, 0.875 representative-neutral clear specificity, and 0.017 ms classification p95; candidate precision was correctly unmeasured because the narrow classifier made zero holdout predictions. Replaying 1,048 visible summaries produced conditional rather than false-clear clearance with aggregate-only uncertainty.",
      "linked_ids": [
        "REQ-174",
        "TRK-161",
        "IMP-014",
        "WFR-431",
        "WFR-432",
        "WFR-433",
        "WFR-434"
      ],
      "created_at": "2026-07-25",
      "commands": [
        {
          "command": "python scripts/reason_guard_benchmark.py --samples 100 --warmup 10 --evaluation-split holdout --json",
          "outcome": "passed bounded accuracy and latency budget"
        },
        {
          "command": "python scripts/prd_workflows.py retry WFR-434 --json",
          "outcome": "1266 tests and every release gate passed after two audit fixes"
        },
        {
          "command": "python -m pytest system_tests -v",
          "outcome": "12 passed, 6 optional live-host scenarios skipped"
        },
        {
          "command": "active Codex visible-summary replay through prd_reason_guard.process_event",
          "outcome": "1048 observed, 1 candidate, 372 uncertain, 675 ignored, conditional clearance"
        }
      ],
      "limitations": "The final holdout produced no high-confidence candidate predictions, so candidate precision is null rather than claimed as 1.0. Six optional system scenarios requiring live OpenCode were skipped; their mock equivalents and shared harness passed."
    },
    {
      "id": "EV-213",
      "type": "validation",
      "summary": "Reason Guard historical backfill behavior, cross-host parity, privacy boundaries, cursor recovery, and configuration/UI defaults passed focused and full verification.",
      "linked_ids": [
        "REQ-175",
        "TRK-162",
        "IMP-TASK-116",
        "IMP-VAL-102",
        "WFR-442"
      ],
      "created_at": "2026-07-25",
      "commands": [
        {
          "command": "python -m unittest tests.test_reason_guard tests.test_config_toggles tests.test_prd_ui_export tests.test_reason_guard_benchmark -q",
          "outcome": "110 tests passed"
        },
        {
          "command": "python -m unittest discover -s tests -v",
          "outcome": "1275 tests passed in WFR-442"
        },
        {
          "command": "SHA256 source/template hook comparison",
          "outcome": "byte-identical"
        }
      ],
      "limitations": "Validation uses sanitized synthetic rollout fixtures and the existing frozen benchmark corpus; no private reasoning was accessed."
    },
    {
      "id": "EV-214",
      "type": "review",
      "summary": "The 0.16.59 release candidate passed clean re-review, CHML audits, release hygiene, gap audit, state/config checks, and npm package verification.",
      "linked_ids": [
        "REQ-175",
        "TRK-162",
        "IMP-TASK-116",
        "IMP-VAL-102",
        "WFR-439",
        "WFR-440",
        "WFR-442"
      ],
      "created_at": "2026-07-25",
      "commands": [
        {
          "command": "engineering.code-review WFR-440",
          "outcome": "completed with zero findings after fixing two first-pass defects"
        },
        {
          "command": "hub.release WFR-442",
          "outcome": "completed; workflow and Substrate CHML 0; release and gap findings none"
        },
        {
          "command": "npm pack --dry-run",
          "outcome": "prd-plugin 0.16.59 package verified with no local cache artifacts"
        }
      ],
      "limitations": "Registry publication is recorded separately after the version tag is pushed and the published version is read back."
    },
    {
      "id": "EV-215",
      "type": "validation",
      "summary": "PRD Plugin 0.16.59 publication was triggered by pushing main and the annotated v0.16.59 tag to origin after the release workflow passed.",
      "linked_ids": [
        "REQ-175",
        "TRK-162",
        "IMP-TASK-116",
        "IMP-VAL-102",
        "CHG-140",
        "WFR-442"
      ],
      "created_at": "2026-07-25",
      "commands": [
        {
          "command": "git push origin main",
          "outcome": "origin/main advanced to c017e45"
        },
        {
          "command": "git push origin v0.16.59",
          "outcome": "new annotated release tag accepted by origin"
        }
      ],
      "limitations": "Per the hub release policy, a successful tag push is the publication action; registry polling is deferred unless the owner reports a publication failure."
    },
    {
      "id": "EV-216",
      "type": "validation",
      "summary": "Host-specific Reason Guard ledgers retain provider, surface, model, effort, and session identity; bounded offline Claude and Codex historical fixtures backfill visible summaries without private blocks; OpenCode metadata forwarding, migrations, UI reporting, and source/skeleton parity are verified. Focused 139 tests and the full 1,289-test suite passed; benchmark budget passed; state consistency is 0 errors/0 warnings; deterministic workflow CHML is 0/0/0/0.",
      "linked_ids": [
        "REQ-176",
        "TRK-163",
        "PRD-011",
        "ARCH-011",
        "IMP-016",
        "DBR-002"
      ],
      "created_at": "2026-07-25",
      "commands": [
        {
          "command": "focused Reason Guard unittest suite",
          "outcome": "ok",
          "tests_run": 139,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "engineering.verify WFR-448 / npm test",
          "outcome": "ok",
          "tests_run": 1289,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "reason_guard_benchmark.py --samples 100 --warmup 10 --json",
          "outcome": "budget passed",
          "structured_p95_ms": 39.289,
          "delta_p95_ms": 7.147
        },
        {
          "command": "workflow_chml_audit.py --format json",
          "outcome": "ok",
          "critical": 0,
          "high": 0,
          "medium": 0,
          "low": 0
        },
        {
          "command": "state_consistency_check.py --format json",
          "outcome": "ok",
          "errors": 0,
          "warnings": 0
        },
        {
          "command": "node --check .opencode/plugins/prd-hooks.js",
          "outcome": "ok"
        }
      ],
      "limitations": "No live Claude session was run, as requested. Claude behavior was exercised against old trusted transcript fixtures and synthetic privacy/adversarial fixtures; live Claude validation remains intentionally deferred until usage limits permit."
    },
    {
      "id": "EV-217",
      "type": "validation",
      "summary": "The release-boundary workflow completed on its deterministic retry after a transient Windows receipt-save denial. It re-proved CHML zero, Substrate capability parity, the full local workflow suite, release hygiene, version gap hygiene, package contents for prd-plugin 0.16.60, and the canonical state gate.",
      "linked_ids": [
        "REQ-176",
        "TRK-163",
        "IMP-016",
        "EV-216",
        "CHG-141",
        "WFR-451"
      ],
      "created_at": "2026-07-25",
      "commands": [
        {
          "command": "hub.release WFR-451 attempt 2",
          "outcome": "completed"
        },
        {
          "command": "workflow_chml_audit",
          "outcome": "ok",
          "critical": 0,
          "high": 0,
          "medium": 0,
          "low": 0
        },
        {
          "command": "prd_substrate_catalog audit",
          "outcome": "ok",
          "capabilities": 26,
          "runtime_tools": 103,
          "intents": 31
        },
        {
          "command": "local_workflow_check",
          "outcome": "ok",
          "tests_run": 1289,
          "failures": 0,
          "errors": 0
        },
        {
          "command": "release_check and gap_audit",
          "outcome": "ok"
        },
        {
          "command": "npm pack --dry-run package check",
          "outcome": "ok",
          "version": "0.16.60",
          "files": 658
        }
      ],
      "limitations": "No live Claude session was run, as requested. The first release-workflow attempt was interrupted only by a transient Windows atomic replacement denial while persisting workflow-runs.json; deterministic retry completed every release step."
    },
    {
      "id": "EV-218",
      "type": "validation",
      "summary": "Reason Guard precision and evidence affinity shipped at implementation commit 1d1bbe4 with release corrections 6d66ec9 and 347db00. Focused Reason Guard tests passed (94 tests); the benchmark passed with 1.00 candidate precision, 1.00 safety recall, 0.8941 representative-neutral specificity, 0.020 ms classifier p95, 42.541 ms structured p95, and 12.627 ms p95 delta. Hub release workflow WFR-459 passed 1,294 tests, config/state consistency, workflow CHML 0/0/0/0, Substrate capability CHML 0/0/0/0, release hygiene, 0.16.61 gap audit, npm package dry-run, and the state gate with zero errors and warnings.",
      "linked_ids": [
        "REQ-174",
        "REQ-176",
        "TRK-164",
        "WFR-454",
        "WFR-457",
        "WFR-459",
        "IMP-014",
        "IMP-TASK-115",
        "IMP-016",
        "IMP-TASK-117"
      ],
      "created_at": "2026-07-25",
      "commands": [
        {
          "command": "python -m unittest tests.test_reason_guard tests.test_reason_guard_benchmark tests.test_hook_dispatcher",
          "outcome": "94 tests passed"
        },
        {
          "command": "python scripts/reason_guard_benchmark.py --samples 200 --warmup 20 --evaluation-split all --json",
          "outcome": "budget passed; precision 1.00; safety recall 1.00; representative-neutral specificity 0.8941; p95 delta 12.627 ms"
        },
        {
          "command": "python scripts/prd_workflows.py retry WFR-459 --json",
          "outcome": "hub.release completed; 1,294 tests passed; all release/package/state/audit steps completed"
        }
      ],
      "limitations": "No new live Claude session was started. Claude normalization and ingestion behavior were verified with trusted transcript fixtures and the existing captured-session defect corpus; the implementation adds no model, network, service, dependency, or configuration."
    },
    {
      "id": "EV-219",
      "type": "validation",
      "summary": "Verified deterministic current-repository PRD inbox discovery across the MCP surface, downstream install policy, Codex/Claude/OpenCode instruction parity, and the full release boundary.",
      "linked_ids": [
        "REQ-007",
        "TRK-165",
        "WFR-463",
        "WFR-464"
      ],
      "created_at": "2026-07-28",
      "commands": [
        {
          "command": "node --test tests/node/server.test.cjs",
          "outcome": "62/62 passed, including prd_check_messages tool exposure and E2E package discovery"
        },
        {
          "command": "python -m unittest (focused request/message/tool/install/parity/release suites) -q",
          "outcome": "188 passed, 1 skipped"
        },
        {
          "command": "prd_check_messages against D:/Projects/prd-plugin",
          "outcome": "Found the five new inbox packages in the current repo; no false empty report"
        },
        {
          "command": "hub.release WFR-464",
          "outcome": "Completed: 1,296 tests passed with 1 intentional skip; CHML, Substrate, release, gap, package, state, and gate checks passed"
        },
        {
          "command": "engineering.code-review WFR-463",
          "outcome": "Completed with no material findings"
        }
      ],
      "limitations": "No external host UI automation was required; behavior is covered at the shared MCP/tool, install, and host-instruction layers."
    }
  ]
}
