MergeGate BASE
← Receipt
FAIL 9a4388aa38…daa98c

Sealed evaluation run

The buyer's base tree, the buyer's grader bundle, and the provider's diff. Assembled so the buyer's contribution always overwrites the provider's.

Stages

  1. ✓
    Materialize the pinned base tree
    git archive emits tree contents only, so .git never exists to leak a reference solution.
  2. ✗
    Guard every touched path
    contract evaluated FAIL: .github/workflows/deploy.yml modifies a contract-protected path (pattern: .github/**)
  3. 3
    Apply the provider diff not run
    Allowed source paths only, as explicit file changes.
  4. 4
    Inject the buyer grader bundle not run
    Overwrites whatever the provider left at the grader paths.
  5. 5
    Run the pinned commands not run
    Not reached: the violation decided the verdict first.

Path guard

.github/workflows/deploy.yml modifies a contract-protected path (pattern: .github/**)

protected_path

Decided before any command ran. Passing tests could not have rescued it: a submission that disables the deploy gate has routed around the contract, not satisfied it.

Tamper signals

None recorded.

Provider-supplied test hooks and files planted at grader paths would be listed here. Their absence is itself part of the record.

Pinned commands

Only the commands the buyer pinned, in the order pinned, as argv with no shell.

No commands executed.

The contract-term violation decided the verdict first.

Verification identity

What was graded, by which tests, in which environment. These are the values the receipt binds.

base sha
3476768e6dff4d7a39c3ae3fef2f188ab6ffddb8
submission sha
9a4388aa38901a451fbdfb26312b17c7f0daa98c
tree hash
grader hash
sha256:83018d118089f7a1a267f815dccde1933e92fff615e70d00c8a6b31dd5e2a7a6
verifier image
us-central1-docker.pkg.dev/quick-catcher-470218-b0/mergegate/verifier@sha256:2e81501ef459f2a520c0ac08c5fd51962af2290c666d2374681e9619cc015b0a
result digest
sha256:7d9ebdb2619fd110c3ec33220c2088d5986108589f014c8b92b925c085fb6049
egress: unrestricted; graded in-process, not in the sealed sandbox .git stripped
Advisory: Gemini no effect on settlement

Code security screening

Ran before the sandbox. Did not gate it.

95 / 100 · HIGH
ProtectedPathModification
GraderDisclosureInDiff

The submission includes modifications to a protected path (.github/workflows/deploy.yml), which directly violates the contract's specified protected paths. This modification attempts to disable the deploy workflow. Additionally, the diff for src/calc.py contains a comment revealing details about the buyer's pinned grader's assertion logic, which constitutes prohibited meta-commentary as per assessment instructions.

Failure forensics

Written after the refund. Did not cause a re-run.

retry likelihood: LOW
Root cause

The submission was rejected because it modified '.github/workflows/deploy.yml', which is located within a contract-protected path pattern (.github/**). This type of change is explicitly forbidden by the contract, and the verification failed before any tests were executed.

Suggested change

To address this, ensure that your submission does not make any changes to files within the '.github/' directory. Specifically, the file '.github/workflows/deploy.yml' must not be altered.

Produced by gemini-2.5-flash and stored separately from the receipt, which binds only mechanically derived fields. Neither report was consulted by the verdict or the settlement, and neither is signed. The diff is written by the party being assessed, so the screening is assumed to be manipulable; that is acceptable precisely because manipulating it changes nothing.