﻿
===== H17 spec-audit - single-source config live-read =====
  live-read caps: autoinject_cap=25600B  soft_cap=30720B  (memory-budget.json)
  [OK] caps read LIVE from single source (NOT hardcoded; budget.measured is stale - ignored)

===== FACE (a) WRITE-GOVERNANCE (single-writer D9) =====
[SPEC] a:tool-scope     | A1             | PASS   | 20 sub-agent tools[] carry only READ RAG verbs (no store_memory/delete/update)
[SPEC] a:schema         | A2             | PASS   | hmw.js SCHEMA required=[findings,memoryDelta] + writeGuard forbids store_memory/RAG
[SPEC] a:propose-only   | A3             | PASS   | 15 read-only-role agents carry a propose-only/single-writer declaration (PROXY: phrase-presence)

===== FACE (b) CHANGE-GOVERNANCE (composed - D8 one-way + C2/B3) =====
[SPEC] b:detectors      | B1             | PASS   | governance-detectors.ps1 present + ran (exit 0; 50 advisory FLAG surfaced - detector owns the verdict)
[SPEC] b:change-proc    | B2             | PASS   | change-governance route documented (D7 owner-approve / D8 one-way / report-before-stamp)

===== FACE (c) DISTILLATION-SPECTRUM (live byte-measure per agent) =====
[SPEC] c:distill        | C-spectrum     | N/A    | no over-cap agent this run (all MEMORY.md under autoinject_cap - no spectrum required)

===== EVAL-ARM HCV proxy (run-trace harvest completeness) =====
[SPEC] eval:hcv         | HCV            | N/A    | latest run 2026-07-26-S153-bookend-open has no sub-*.md (return-delta-only mode) - proxy N/A

===== CAVEATS / self-blind-spot (honest surface - always emitted) =====
  - C1. Loop "runs" = MANUAL walkthrough chained by em-main (detect -> classify -> record). This script + governance-detectors run exit-0 SEPARATELY; there is NO single auto-run that closes the whole loop each session.
  - C2. Recall/apply JUDGE layer = STUB (mfe-eval -Judge scaffold). Numbers meaningless until sample-questions mature AND an independent cross-session judge scores. Not measured here.
  - C3. HCV harvest-coverage threshold = calibration-interim (single-peak distribution -> tail-flag, NOT a chosen quality bar).
  - C4. Meta-blind-spot: this checker audits the WORKER artifacts (agents/memory/hmw). It does NOT audit the eval/refine/audit meta-arms themselves (the measurer is not yet self-measured).
  - C5. Distillation = compress-only so far. The verify-BEFORE-keep step (validate content before a distill deletes the raw) is NOT built.
  - SCOPE: this checker covers C-face (a)(b)(c) DETERMINISTICALLY + HCV proxy. It does NOT verify B1 signal->action MAP application, B2 CG-1 termination decisions, or A2 load-fidelity NUMBERS (those are separate arms: mfe-eval.ps1 + the reinject-ledger + em-main judgement).
  - BUILD-GAP honest: B1/B2 refine mechanics are convention (em-main hand); the reinject-ledger is a git-tracked append-only record, NOT an auto-writer. Do not read "checker silent" as "fully compliant".
  - D9 ENFORCEMENT honest: single-writer is wired by TOOL-SCOPE (A1) + SCHEMA (A2) - NOT by an OS hook (.claude/settings.json has none; store_memory allowlist-strip is AS-10/E-006 fails-open). A3 is a PROXY. This proves guards are WIRED, not that runtime CANNOT violate.

===== Summary (criteria-set + gap-set - re-computed LIVE each run) =====
CRITERIA (this run, LIVE): A1 A2 A3 B1 B2
GAPS (this run): none

NOTE: H17 PART-C spec-audit. CRITERIA+GAP set is the output (NOT a frozen score - it drifts as artifacts self-heal). Exit 0 always (advisory). Cite the GAP-set, not a tally.
