# Security-agent preparation evidence

Captured on October 4, 2026. This package accompanies the article **Freeze the evidence before you measure a security agent**. It contains preparation evidence, not a scored model comparison.

The two cases are an author-created HTTP/SQLite fixture with public test identities and marker data. They are one defective lookup and its fixed control. The observed labels are supported by real local HTTP checks; peer adjudication is pending. No model or paid Exa/Parallel calls have run.

- [Public summary](./public-summary.json): status, tool identities, packet sizes, unknown metrics, and planned schedule.
- [HTTP verification](./verification.json): all fourteen receiver observations, including the two prohibited reads that succeeded in case-01.
- [Checksums](./SHA256SUMS): SHA-256 for every exported evidence file except the checksum list itself.
- [Integration-check log](./validation/test-run.txt) and [validation identities](./validation/test-run.json): an October 4 recheck with eight passing tests and no paid provider or scored model calls. Model receipts used in the tests are synthetic. The complete private study harness is not bundled here; the record includes its tested source hashes. This is author-local validation, not independent peer replication.

## Packets and runnable source

Each case directory contains `sources/auth.py`, `sources/repository.py`, and `sources/server.py`. The source is a toy study fixture with public bearer identities, not production authentication. Python 3.9 or later can start it with `python3 server.py` from that case's `sources` directory. It binds to localhost on an ephemeral port and prints the selected port. The recorded HTTP observations identify the actors, records, responses, and expected statuses.

| Artifact | case-01: defective | case-02: fixed control |
| --- | --- | --- |
| Ordinary packet | [Bundle](./case-01/baseline.bundle.md) | [Bundle](./case-02/baseline.bundle.md) |
| Distill packet | [Bundle](./case-01/distill/context.bundle.md) | [Bundle](./case-02/distill/context.bundle.md) |
| Build facts | [Packet report](./case-01/packet-report.json) | [Packet report](./case-02/packet-report.json) |
| Distill configuration | [Config](./case-01/config.json) | [Config](./case-02/config.json) |
| Distill lock | [Lock](./case-01/context.lock.json) | [Lock](./case-02/context.lock.json) |
| Inclusion and bundle identity | [Manifest](./case-01/distill/context.manifest.json) | [Manifest](./case-02/distill/context.manifest.json) |
| Evidence locations | [Map](./case-01/evidence-map.json) | [Map](./case-02/evidence-map.json) |
| Deduplicated chunk locations | [Map](./case-01/chunk-evidence-map.json) | [Map](./case-02/chunk-evidence-map.json) |
| Authentication source | [Source](./case-01/sources/auth.py) | [Source](./case-02/sources/auth.py) |
| Record lookup source | [Source](./case-01/sources/repository.py) | [Source](./case-02/sources/repository.py) |
| HTTP server source | [Source](./case-01/sources/server.py) | [Source](./case-02/sources/server.py) |

[Distill](https://github.com/Siddhant-K-code/distill) was built at [commit 2417e00](https://github.com/Siddhant-K-code/distill/commit/2417e00dabe498eb8187f4544f001d5a49fbdb45) with Go 1.26.4. The [pinned Lock specification](https://github.com/Siddhant-K-code/distill/blob/2417e00dabe498eb8187f4544f001d5a49fbdb45/docs/distill-lock-v0.md) describes its artifact contract. The copied configuration, sources, lock, and output files preserve their original saved bytes. Run the pinned tool's `build --help` and `verify --help` for supported options. Packet build times are observed preparation timings, not controlled performance comparisons. `selected_tokens` is Distill's byte-based estimate and is not provider usage.

The baseline and Distill bundle hashes are stored in each packet report. All three unique source files were included. Neither case contained duplicate chunks or omitted unique content. Both Distill packets are 490 bytes larger than their ordinary counterparts.

## Public Sourcegraph capture and later advisory candidate

- [Request](./sourcegraph/request.json), [capture metadata](./sourcegraph/capture.json), and [exact saved SSE response](./sourcegraph/response.raw).
- [Next.js source index](./nextjs-source-index.json): fourteen files fetched through GitHub, with source URLs, pinned revisions, saved sizes/hashes, and the disclosed text-normalization method. Full Next.js file bodies are not bundled in this export.

The completed Sourcegraph query returned seven line matches in two files at [Next.js commit 4698ad6](https://github.com/vercel/next.js/commit/4698ad6478cc85a7283a8c41edfbba023dadf57d). No skipped results were reported. The initial restricted-network transport failure remains in the private study and is disclosed in the public summary. The response time of 4.778 seconds is one request observation. Sourcegraph cost is unknown. Narrow-query completion does not establish whole-repository coverage or Next.js exploitability. The known [Next.js advisory](https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw) and [fix commit](https://github.com/vercel/next.js/commit/52a078da3884efe6501613c7834a3d02a91676d2) are a later walkthrough candidate, not a novel finding or a historical evidence snapshot.

## Native agent-trace export

- [Metadata](./agent-trace/meta.json) and [events](./agent-trace/events.ndjson).

The real [native reader](https://github.com/Siddhant-K-code/agent-trace/blob/b109ec5b3714b842746e97ee8e975329d8582667/src/agent_trace/store.py) and [timeline](https://github.com/Siddhant-K-code/agent-trace/blob/b109ec5b3714b842746e97ee8e975329d8582667/src/agent_trace/timeline.py) loaded this two-event export at [agent-trace commit b109ec5](https://github.com/Siddhant-K-code/agent-trace/commit/b109ec5b3714b842746e97ee8e975329d8582667). It contains session lifecycle events and posthoc controller verification observations. It has no model request/response events and no recorded model token usage. Native redaction replaced selected public fixture hash fields; the complete hashes and observations remain in `verification.json`.

The future twelve-run schedule is still a plan. No finding-quality, token, billing, or end-to-end efficiency result is available from this package.
