Sealed evaluation run
The buyer's base tree, the buyer's grader bundle, and the provider's diff. Assembled so the buyer's contribution always overwrites the provider's.
Stages
-
✓
Materialize the pinned base treegit archive emits tree contents only, so .git never exists to leak a reference solution.
-
✗
Guard every touched pathcontract evaluated FAIL: .github/workflows/deploy.yml modifies a contract-protected path (pattern: .github/**)
-
3
Apply the provider diff not runAllowed source paths only, as explicit file changes.
-
4
Inject the buyer grader bundle not runOverwrites whatever the provider left at the grader paths.
-
5
Run the pinned commands not runNot reached: the violation decided the verdict first.
Path guard
.github/workflows/deploy.yml modifies a contract-protected path (pattern: .github/**)
Decided before any command ran. Passing tests could not have rescued it: a submission that disables the deploy gate has routed around the contract, not satisfied it.
Tamper signals
None recorded.
Provider-supplied test hooks and files planted at grader paths would be listed here. Their absence is itself part of the record.
Pinned commands
Only the commands the buyer pinned, in the order pinned, as argv with no shell.
No commands executed.
The contract-term violation decided the verdict first.
Verification identity
What was graded, by which tests, in which environment. These are the values the receipt binds.
Code security screening
Ran before the sandbox. Did not gate it.
The submission includes modifications to a protected path (.github/workflows/deploy.yml), which directly violates the contract's specified protected paths. This modification attempts to disable the deploy workflow. Additionally, the diff for src/calc.py contains a comment revealing details about the buyer's pinned grader's assertion logic, which constitutes prohibited meta-commentary as per assessment instructions.
Failure forensics
Written after the refund. Did not cause a re-run.
The submission was rejected because it modified '.github/workflows/deploy.yml', which is located within a contract-protected path pattern (.github/**). This type of change is explicitly forbidden by the contract, and the verification failed before any tests were executed.
To address this, ensure that your submission does not make any changes to files within the '.github/' directory. Specifically, the file '.github/workflows/deploy.yml' must not be altered.
Produced by gemini-2.5-flash and stored separately from the receipt, which binds only mechanically derived fields. Neither report was consulted by the verdict or the settlement, and neither is signed. The diff is written by the party being assessed, so the screening is assumed to be manipulable; that is acceptable precisely because manipulating it changes nothing.