{
  "schemaVersion": "cg-agent-intent-conformance-fixture-0.1.0",
  "id": "CG-FIXTURE-AGENT-INTENT-CONFORMANCE-0.1.0",
  "benchmarkId": "CG-BENCHMARK-AGENT-INTENT-CONFORMANCE-0.1.0",
  "version": "0.1.0",
  "authorization": "Publisher-created inert fixtures with synthetic identities and content digests; no customer data, external agent, shell command, file mutation, or network action is executed.",
  "syntheticKeyNotice": "All public keys and signatures belong only to this deterministic fixture and are not production trust material.",
  "times": {
    "issuedAt": "2026-07-30T00:00:00.000Z",
    "activeAt": "2026-07-30T00:30:00.000Z",
    "expiresAt": "2026-07-30T01:00:00.000Z"
  },
  "bindings": {
    "actorId": "agent.intent-benchmark",
    "taskId": "task.intent-conformance-benchmark",
    "sessionId": "CGS-INTENT-CONFORMANCE-0001",
    "objectiveDigestSha256": "9e93a1c8c7ff09e45e6a1813eb5b8af8eae7d739f5289aa5df4e853c68efaef1",
    "policyDigestSha256": "0e1654c1636f19b0ca8a27af2691d328ef5fd7d9d6cb5388d755e40073b7e4bd"
  },
  "authorityPublicKeys": {
    "trusted": [
      "-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEASAdaWX5yGhVuLgeZ3lzAxTJNxufq8c3UYlCGjsUyFd0=\n-----END PUBLIC KEY-----\n",
      "-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEAXiEsCYDks5/AlyETSqAhCTdO39JgwNPQPLUByNZUV6k=\n-----END PUBLIC KEY-----\n"
    ],
    "untrusted": "-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEAF8t5+ytBIPKx7GXkGY1uCLKOgT/rAeSkAIObheGAgM4=\n-----END PUBLIC KEY-----\n",
    "state": "-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEA25lf4lFp0UHKubu6krqgH58uHs599MsqwFGQ83/MH50=\n-----END PUBLIC KEY-----\n"
  },
  "contracts": {
    "base": {
      "actorBindingSha256": "ede98450d1e7777ce04cb0f5e1fc26c4ea9edd72b91ffa7669f14894fde3054e",
      "claimBoundary": "CapitalGuard Agent Intent Firewall 0.1 enforces only operations routed through its owned callback against a finite threshold-signed, actor-bound, task-bound, session-bound execution graph. It deterministically verifies step order, exact operation selectors, use limits, replay state, and atomic pre-invocation reservations. It does not infer semantic intent from prose, prove approver understanding, inspect bypassed operations, reverse completed actions, reconcile uncertain outcomes automatically, resist host or threshold-authority compromise, or detect coordinated rollback of both state and its external anchor.",
      "contractId": "CGIFC-INTENT-CONFORMANCE-BASE",
      "expiresAt": "2026-07-30T01:00:00.000Z",
      "issuedAt": "2026-07-30T00:00:00.000Z",
      "maxTotalActions": 6,
      "objectiveDigestSha256": "9e93a1c8c7ff09e45e6a1813eb5b8af8eae7d739f5289aa5df4e853c68efaef1",
      "policyDigestSha256": "0e1654c1636f19b0ca8a27af2691d328ef5fd7d9d6cb5388d755e40073b7e4bd",
      "requiredSignatures": 2,
      "schemaVersion": "cg-agent-intent-contract-0.1.0",
      "sessionBindingSha256": "67fd53f3979f73180f7848808f3bef6fdfbc65a436d6a3fc40c4fcdd10e614f3",
      "steps": [
        {
          "dependsOn": [
            "step.write"
          ],
          "maxUses": 1,
          "operation": "command.execute",
          "purposeCode": "review",
          "selector": {
            "targets": [
              {
                "argumentDigests": [
                  "7e220b8eca0697a5a98dfbdcc8d502452da860fbb854854948b3904ca7d5f7c1"
                ],
                "executable": "git"
              }
            ]
          },
          "stepId": "step.command"
        },
        {
          "dependsOn": [
            "step.read"
          ],
          "maxUses": 1,
          "operation": "mcp.tool.invoke",
          "purposeCode": "review",
          "selector": {
            "targets": [
              {
                "argumentDigests": [
                  "ebf96c008e970bad13981ae7c36a4e1df5ad21a4a1f18e55ea3253754adb74ce"
                ],
                "server": "server.github",
                "tool": "issue.get"
              }
            ]
          },
          "stepId": "step.mcp"
        },
        {
          "dependsOn": [],
          "maxUses": 1,
          "operation": "network.connect",
          "purposeCode": "collect",
          "selector": {
            "targets": [
              {
                "host": "status.example.com",
                "pathDigests": [
                  "8818598459ccdd963e58fa2850ab20acea0f67b5d853030b109a3dd72c6cde72"
                ]
              }
            ]
          },
          "stepId": "step.network"
        },
        {
          "dependsOn": [],
          "maxUses": 2,
          "operation": "file.read",
          "purposeCode": "analyze",
          "selector": {
            "targets": [
              {
                "match": "prefix",
                "path": "src/"
              }
            ]
          },
          "stepId": "step.read"
        },
        {
          "dependsOn": [
            "step.read"
          ],
          "maxUses": 1,
          "operation": "file.write",
          "purposeCode": "modify",
          "selector": {
            "targets": [
              {
                "contentDigests": [
                  "059b4c004e1e4f8e3e2b8c753290579bfa08189cf30ead19bfd181e2425701fc"
                ],
                "match": "exact",
                "path": "src/output.txt"
              }
            ]
          },
          "stepId": "step.write"
        }
      ],
      "taskBindingSha256": "3f78f3ea4b0f7646d22910ab3f24d830091a1b86625c5977cea4c2574199ea95",
      "version": "0.1.0",
      "semanticDigestSha256": "39864aa091fec06e5e7b275eb3f4bc2238c4445f905ee142b331c0320354f176",
      "signatures": [
        {
          "algorithm": "ed25519",
          "keySha256": "76fe9485d6ac496f8650ecfc2b3c363e4cfa5c0af83df501296dc531716f008e",
          "value": "85yd1nfe7O+HS4dumcoGlz3iX97TxQIiSgIcQ3DY71AMRpNa8x1JvmoqZ4nFnNZUx0YYkvedUbnYrQ/Xaq6qBA=="
        },
        {
          "algorithm": "ed25519",
          "keySha256": "cf164fe3ff0a4b3096858690da512099b3b7f8d866b2b27c7527e112f83e8cc3",
          "value": "srsmKZv2+tQcQyqronKLIe2KwXu+X/vdTmzEXhOy4V7sAEOXNkoRUObpCNuT2DCM6iJljJCRpy/lBiOoT1cjCw=="
        }
      ]
    },
    "singleUse": {
      "actorBindingSha256": "ede98450d1e7777ce04cb0f5e1fc26c4ea9edd72b91ffa7669f14894fde3054e",
      "claimBoundary": "CapitalGuard Agent Intent Firewall 0.1 enforces only operations routed through its owned callback against a finite threshold-signed, actor-bound, task-bound, session-bound execution graph. It deterministically verifies step order, exact operation selectors, use limits, replay state, and atomic pre-invocation reservations. It does not infer semantic intent from prose, prove approver understanding, inspect bypassed operations, reverse completed actions, reconcile uncertain outcomes automatically, resist host or threshold-authority compromise, or detect coordinated rollback of both state and its external anchor.",
      "contractId": "CGIFC-INTENT-CONFORMANCE-SINGLE",
      "expiresAt": "2026-07-30T01:00:00.000Z",
      "issuedAt": "2026-07-30T00:00:00.000Z",
      "maxTotalActions": 1,
      "objectiveDigestSha256": "9e93a1c8c7ff09e45e6a1813eb5b8af8eae7d739f5289aa5df4e853c68efaef1",
      "policyDigestSha256": "0e1654c1636f19b0ca8a27af2691d328ef5fd7d9d6cb5388d755e40073b7e4bd",
      "requiredSignatures": 2,
      "schemaVersion": "cg-agent-intent-contract-0.1.0",
      "sessionBindingSha256": "67fd53f3979f73180f7848808f3bef6fdfbc65a436d6a3fc40c4fcdd10e614f3",
      "steps": [
        {
          "dependsOn": [],
          "maxUses": 1,
          "operation": "file.read",
          "purposeCode": "analyze",
          "selector": {
            "targets": [
              {
                "match": "prefix",
                "path": "src/"
              }
            ]
          },
          "stepId": "step.read"
        }
      ],
      "taskBindingSha256": "3f78f3ea4b0f7646d22910ab3f24d830091a1b86625c5977cea4c2574199ea95",
      "version": "0.1.0",
      "semanticDigestSha256": "0ce4c8effe3c45dd5ac34155231515d7ef76dce0901b2c11dce9a57122578307",
      "signatures": [
        {
          "algorithm": "ed25519",
          "keySha256": "76fe9485d6ac496f8650ecfc2b3c363e4cfa5c0af83df501296dc531716f008e",
          "value": "xInm42twQeifaagtmwjs8rplesou5AzSePVY2iJgVHrY80VcZPi/9H3bwV/6gohLImMEuHMQrS54JiIA1NfbAg=="
        },
        {
          "algorithm": "ed25519",
          "keySha256": "cf164fe3ff0a4b3096858690da512099b3b7f8d866b2b27c7527e112f83e8cc3",
          "value": "jY0gImMkt0cHRLoReE032ML0bN6V7Rjsr/f8T7MWnmKvw1xfWZBAxhT2A3CGs8vqryThwgNqRD8K4t/+g5aJAA=="
        }
      ]
    },
    "thresholdIncomplete": {
      "actorBindingSha256": "ede98450d1e7777ce04cb0f5e1fc26c4ea9edd72b91ffa7669f14894fde3054e",
      "claimBoundary": "CapitalGuard Agent Intent Firewall 0.1 enforces only operations routed through its owned callback against a finite threshold-signed, actor-bound, task-bound, session-bound execution graph. It deterministically verifies step order, exact operation selectors, use limits, replay state, and atomic pre-invocation reservations. It does not infer semantic intent from prose, prove approver understanding, inspect bypassed operations, reverse completed actions, reconcile uncertain outcomes automatically, resist host or threshold-authority compromise, or detect coordinated rollback of both state and its external anchor.",
      "contractId": "CGIFC-INTENT-CONFORMANCE-THRESHOLD",
      "expiresAt": "2026-07-30T01:00:00.000Z",
      "issuedAt": "2026-07-30T00:00:00.000Z",
      "maxTotalActions": 6,
      "objectiveDigestSha256": "9e93a1c8c7ff09e45e6a1813eb5b8af8eae7d739f5289aa5df4e853c68efaef1",
      "policyDigestSha256": "0e1654c1636f19b0ca8a27af2691d328ef5fd7d9d6cb5388d755e40073b7e4bd",
      "requiredSignatures": 2,
      "schemaVersion": "cg-agent-intent-contract-0.1.0",
      "sessionBindingSha256": "67fd53f3979f73180f7848808f3bef6fdfbc65a436d6a3fc40c4fcdd10e614f3",
      "steps": [
        {
          "dependsOn": [
            "step.write"
          ],
          "maxUses": 1,
          "operation": "command.execute",
          "purposeCode": "review",
          "selector": {
            "targets": [
              {
                "argumentDigests": [
                  "7e220b8eca0697a5a98dfbdcc8d502452da860fbb854854948b3904ca7d5f7c1"
                ],
                "executable": "git"
              }
            ]
          },
          "stepId": "step.command"
        },
        {
          "dependsOn": [
            "step.read"
          ],
          "maxUses": 1,
          "operation": "mcp.tool.invoke",
          "purposeCode": "review",
          "selector": {
            "targets": [
              {
                "argumentDigests": [
                  "ebf96c008e970bad13981ae7c36a4e1df5ad21a4a1f18e55ea3253754adb74ce"
                ],
                "server": "server.github",
                "tool": "issue.get"
              }
            ]
          },
          "stepId": "step.mcp"
        },
        {
          "dependsOn": [],
          "maxUses": 1,
          "operation": "network.connect",
          "purposeCode": "collect",
          "selector": {
            "targets": [
              {
                "host": "status.example.com",
                "pathDigests": [
                  "8818598459ccdd963e58fa2850ab20acea0f67b5d853030b109a3dd72c6cde72"
                ]
              }
            ]
          },
          "stepId": "step.network"
        },
        {
          "dependsOn": [],
          "maxUses": 2,
          "operation": "file.read",
          "purposeCode": "analyze",
          "selector": {
            "targets": [
              {
                "match": "prefix",
                "path": "src/"
              }
            ]
          },
          "stepId": "step.read"
        },
        {
          "dependsOn": [
            "step.read"
          ],
          "maxUses": 1,
          "operation": "file.write",
          "purposeCode": "modify",
          "selector": {
            "targets": [
              {
                "contentDigests": [
                  "059b4c004e1e4f8e3e2b8c753290579bfa08189cf30ead19bfd181e2425701fc"
                ],
                "match": "exact",
                "path": "src/output.txt"
              }
            ]
          },
          "stepId": "step.write"
        }
      ],
      "taskBindingSha256": "3f78f3ea4b0f7646d22910ab3f24d830091a1b86625c5977cea4c2574199ea95",
      "version": "0.1.0",
      "semanticDigestSha256": "48e07404fd6c43fe2b4f56505d0ba86148677607a9d5d9b91c32881347fb6167",
      "signatures": [
        {
          "algorithm": "ed25519",
          "keySha256": "cf164fe3ff0a4b3096858690da512099b3b7f8d866b2b27c7527e112f83e8cc3",
          "value": "Np/8G58MJwjnTFmSPOnBI5pkcPNxp+RrWiJKq2NJEVd3NN6U8mIVptjgV52uBxyO/L1e2A5OsYjEoP4b4LGaBQ=="
        }
      ]
    },
    "untrusted": {
      "actorBindingSha256": "ede98450d1e7777ce04cb0f5e1fc26c4ea9edd72b91ffa7669f14894fde3054e",
      "claimBoundary": "CapitalGuard Agent Intent Firewall 0.1 enforces only operations routed through its owned callback against a finite threshold-signed, actor-bound, task-bound, session-bound execution graph. It deterministically verifies step order, exact operation selectors, use limits, replay state, and atomic pre-invocation reservations. It does not infer semantic intent from prose, prove approver understanding, inspect bypassed operations, reverse completed actions, reconcile uncertain outcomes automatically, resist host or threshold-authority compromise, or detect coordinated rollback of both state and its external anchor.",
      "contractId": "CGIFC-INTENT-CONFORMANCE-UNTRUSTED",
      "expiresAt": "2026-07-30T01:00:00.000Z",
      "issuedAt": "2026-07-30T00:00:00.000Z",
      "maxTotalActions": 6,
      "objectiveDigestSha256": "9e93a1c8c7ff09e45e6a1813eb5b8af8eae7d739f5289aa5df4e853c68efaef1",
      "policyDigestSha256": "0e1654c1636f19b0ca8a27af2691d328ef5fd7d9d6cb5388d755e40073b7e4bd",
      "requiredSignatures": 2,
      "schemaVersion": "cg-agent-intent-contract-0.1.0",
      "sessionBindingSha256": "67fd53f3979f73180f7848808f3bef6fdfbc65a436d6a3fc40c4fcdd10e614f3",
      "steps": [
        {
          "dependsOn": [
            "step.write"
          ],
          "maxUses": 1,
          "operation": "command.execute",
          "purposeCode": "review",
          "selector": {
            "targets": [
              {
                "argumentDigests": [
                  "7e220b8eca0697a5a98dfbdcc8d502452da860fbb854854948b3904ca7d5f7c1"
                ],
                "executable": "git"
              }
            ]
          },
          "stepId": "step.command"
        },
        {
          "dependsOn": [
            "step.read"
          ],
          "maxUses": 1,
          "operation": "mcp.tool.invoke",
          "purposeCode": "review",
          "selector": {
            "targets": [
              {
                "argumentDigests": [
                  "ebf96c008e970bad13981ae7c36a4e1df5ad21a4a1f18e55ea3253754adb74ce"
                ],
                "server": "server.github",
                "tool": "issue.get"
              }
            ]
          },
          "stepId": "step.mcp"
        },
        {
          "dependsOn": [],
          "maxUses": 1,
          "operation": "network.connect",
          "purposeCode": "collect",
          "selector": {
            "targets": [
              {
                "host": "status.example.com",
                "pathDigests": [
                  "8818598459ccdd963e58fa2850ab20acea0f67b5d853030b109a3dd72c6cde72"
                ]
              }
            ]
          },
          "stepId": "step.network"
        },
        {
          "dependsOn": [],
          "maxUses": 2,
          "operation": "file.read",
          "purposeCode": "analyze",
          "selector": {
            "targets": [
              {
                "match": "prefix",
                "path": "src/"
              }
            ]
          },
          "stepId": "step.read"
        },
        {
          "dependsOn": [
            "step.read"
          ],
          "maxUses": 1,
          "operation": "file.write",
          "purposeCode": "modify",
          "selector": {
            "targets": [
              {
                "contentDigests": [
                  "059b4c004e1e4f8e3e2b8c753290579bfa08189cf30ead19bfd181e2425701fc"
                ],
                "match": "exact",
                "path": "src/output.txt"
              }
            ]
          },
          "stepId": "step.write"
        }
      ],
      "taskBindingSha256": "3f78f3ea4b0f7646d22910ab3f24d830091a1b86625c5977cea4c2574199ea95",
      "version": "0.1.0",
      "semanticDigestSha256": "ba34c0a7e7f7f4d8b8a7dfc620de941450512c3407b3d74f1f2db07b115c3537",
      "signatures": [
        {
          "algorithm": "ed25519",
          "keySha256": "3532fb2b134488a2a18f2a07cd6db85b4c1b808ddb10972f0ad5526856177bd4",
          "value": "h+zyo5UXcZdoGHl1s6BSQw9jEysl5RQFGXMrab9EzLMKITEtV3UML+mzNKO0zSMYVvOV7K+YZ6azhUS9b8H5Bw=="
        },
        {
          "algorithm": "ed25519",
          "keySha256": "cf164fe3ff0a4b3096858690da512099b3b7f8d866b2b27c7527e112f83e8cc3",
          "value": "LiEubyEIeJkExvzsFuSUqY0FJ0o+vPx0ijyd3WBK+ahJ7NESvtD+RhuLdpVPbcJX0ING+tV0iBNWKWn1vDn+Cw=="
        }
      ]
    }
  },
  "requests": {
    "read": {
      "actorId": "agent.intent-benchmark",
      "contextTrust": "untrusted",
      "dataClassification": "internal",
      "environment": "local",
      "evidenceRefs": [],
      "operation": "file.read",
      "requestId": "CGR-3F5637410846D545FB4F35D3",
      "resource": {
        "path": "src/input.ts"
      },
      "schemaVersion": "cg-policy-request-0.1.0",
      "taskId": "task.intent-conformance-benchmark",
      "toolId": "tool.intent-conformance"
    },
    "write": {
      "actorId": "agent.intent-benchmark",
      "contextTrust": "untrusted",
      "dataClassification": "internal",
      "environment": "local",
      "evidenceRefs": [],
      "operation": "file.write",
      "requestId": "CGR-A970EC592DD9E24DE0172789",
      "resource": {
        "contentDigestSha256": "059b4c004e1e4f8e3e2b8c753290579bfa08189cf30ead19bfd181e2425701fc",
        "path": "src/output.txt"
      },
      "schemaVersion": "cg-policy-request-0.1.0",
      "taskId": "task.intent-conformance-benchmark",
      "toolId": "tool.intent-conformance"
    },
    "wrongActor": {
      "actorId": "agent.attacker",
      "contextTrust": "untrusted",
      "dataClassification": "internal",
      "environment": "local",
      "evidenceRefs": [],
      "operation": "file.read",
      "requestId": "CGR-CFFA97B7F2F5B3DA670C9C01",
      "resource": {
        "path": "src/input.ts"
      },
      "schemaVersion": "cg-policy-request-0.1.0",
      "taskId": "task.intent-conformance-benchmark",
      "toolId": "tool.intent-conformance"
    },
    "wrongPath": {
      "actorId": "agent.intent-benchmark",
      "contextTrust": "untrusted",
      "dataClassification": "internal",
      "environment": "local",
      "evidenceRefs": [],
      "operation": "file.write",
      "requestId": "CGR-011E630A02102AA81E95167D",
      "resource": {
        "contentDigestSha256": "059b4c004e1e4f8e3e2b8c753290579bfa08189cf30ead19bfd181e2425701fc",
        "path": "secrets/export.txt"
      },
      "schemaVersion": "cg-policy-request-0.1.0",
      "taskId": "task.intent-conformance-benchmark",
      "toolId": "tool.intent-conformance"
    },
    "wrongContent": {
      "actorId": "agent.intent-benchmark",
      "contextTrust": "untrusted",
      "dataClassification": "internal",
      "environment": "local",
      "evidenceRefs": [],
      "operation": "file.write",
      "requestId": "CGR-E738A70B5E2D513B29879206",
      "resource": {
        "contentDigestSha256": "9f0469b1794e0c5f355b5564ca114fe9e1e82325040453a76cf31d3a4cd4801b",
        "path": "src/output.txt"
      },
      "schemaVersion": "cg-policy-request-0.1.0",
      "taskId": "task.intent-conformance-benchmark",
      "toolId": "tool.intent-conformance"
    },
    "wrongCommand": {
      "actorId": "agent.intent-benchmark",
      "contextTrust": "untrusted",
      "dataClassification": "internal",
      "environment": "local",
      "evidenceRefs": [],
      "operation": "command.execute",
      "requestId": "CGR-F87EDB008B97F5B03B8C55CC",
      "resource": {
        "argumentsDigestSha256": "70d88e834b8114babb46704d9938b080bd3d166710816f3f6687fd52f7284210",
        "executable": "git"
      },
      "schemaVersion": "cg-policy-request-0.1.0",
      "taskId": "task.intent-conformance-benchmark",
      "toolId": "tool.intent-conformance"
    },
    "wrongNetwork": {
      "actorId": "agent.intent-benchmark",
      "contextTrust": "untrusted",
      "dataClassification": "internal",
      "environment": "local",
      "evidenceRefs": [],
      "operation": "network.connect",
      "requestId": "CGR-1DC37A1444F6AABC0536A412",
      "resource": {
        "host": "attacker.example.net",
        "method": "HEAD",
        "pathDigestSha256": "8818598459ccdd963e58fa2850ab20acea0f67b5d853030b109a3dd72c6cde72"
      },
      "schemaVersion": "cg-policy-request-0.1.0",
      "taskId": "task.intent-conformance-benchmark",
      "toolId": "tool.intent-conformance"
    },
    "replay": {
      "actorId": "agent.intent-benchmark",
      "contextTrust": "untrusted",
      "dataClassification": "internal",
      "environment": "local",
      "evidenceRefs": [],
      "operation": "file.read",
      "requestId": "CGR-92D23F5381EAC5178010DCAD",
      "resource": {
        "path": "src/replay.ts"
      },
      "schemaVersion": "cg-policy-request-0.1.0",
      "taskId": "task.intent-conformance-benchmark",
      "toolId": "tool.intent-conformance"
    },
    "concurrentOne": {
      "actorId": "agent.intent-benchmark",
      "contextTrust": "untrusted",
      "dataClassification": "internal",
      "environment": "local",
      "evidenceRefs": [],
      "operation": "file.read",
      "requestId": "CGR-BE95B5B220E638F6EA9D6638",
      "resource": {
        "path": "src/a.ts"
      },
      "schemaVersion": "cg-policy-request-0.1.0",
      "taskId": "task.intent-conformance-benchmark",
      "toolId": "tool.intent-conformance"
    },
    "concurrentTwo": {
      "actorId": "agent.intent-benchmark",
      "contextTrust": "untrusted",
      "dataClassification": "internal",
      "environment": "local",
      "evidenceRefs": [],
      "operation": "file.read",
      "requestId": "CGR-30EF1B168B05F569EDD9F66B",
      "resource": {
        "path": "src/b.ts"
      },
      "schemaVersion": "cg-policy-request-0.1.0",
      "taskId": "task.intent-conformance-benchmark",
      "toolId": "tool.intent-conformance"
    },
    "timeout": {
      "actorId": "agent.intent-benchmark",
      "contextTrust": "untrusted",
      "dataClassification": "internal",
      "environment": "local",
      "evidenceRefs": [],
      "operation": "file.read",
      "requestId": "CGR-AB5B50C3846CCFEF52997E6E",
      "resource": {
        "path": "src/timeout.ts"
      },
      "schemaVersion": "cg-policy-request-0.1.0",
      "taskId": "task.intent-conformance-benchmark",
      "toolId": "tool.intent-conformance"
    },
    "timeoutRetry": {
      "actorId": "agent.intent-benchmark",
      "contextTrust": "untrusted",
      "dataClassification": "internal",
      "environment": "local",
      "evidenceRefs": [],
      "operation": "file.read",
      "requestId": "CGR-01E74FF2669A18AAD53472A4",
      "resource": {
        "path": "src/timeout-retry.ts"
      },
      "schemaVersion": "cg-policy-request-0.1.0",
      "taskId": "task.intent-conformance-benchmark",
      "toolId": "tool.intent-conformance"
    }
  },
  "scenarios": [
    {
      "id": "CGAIC-TV-001",
      "title": "Approved read then write sequence",
      "boundary": "declared plan",
      "mutation": "none",
      "expected": "accepted"
    },
    {
      "id": "CGAIC-TV-002",
      "title": "Signature threshold is incomplete",
      "boundary": "approval threshold",
      "mutation": "one of two required signatures omitted",
      "expected": "rejected"
    },
    {
      "id": "CGAIC-TV-003",
      "title": "Contract contains an untrusted signature",
      "boundary": "trusted approvers",
      "mutation": "second signature created by an unknown authority",
      "expected": "rejected"
    },
    {
      "id": "CGAIC-TV-004",
      "title": "Signed objective digest is changed",
      "boundary": "contract integrity",
      "mutation": "objective digest changed after signing",
      "expected": "rejected"
    },
    {
      "id": "CGAIC-TV-005",
      "title": "Request actor differs from signed actor",
      "boundary": "actor binding",
      "mutation": "request actor changed",
      "expected": "rejected"
    },
    {
      "id": "CGAIC-TV-006",
      "title": "Contract is used after expiry",
      "boundary": "time binding",
      "mutation": "verification time moved to contract expiry",
      "expected": "rejected"
    },
    {
      "id": "CGAIC-TV-007",
      "title": "Request names an undeclared step",
      "boundary": "closed graph",
      "mutation": "step identifier absent from signed graph",
      "expected": "rejected"
    },
    {
      "id": "CGAIC-TV-008",
      "title": "Write runs before its read dependency",
      "boundary": "dependency order",
      "mutation": "dependent step invoked first",
      "expected": "rejected"
    },
    {
      "id": "CGAIC-TV-009",
      "title": "Write path differs from approved path",
      "boundary": "file target",
      "mutation": "approved output path replaced",
      "expected": "rejected"
    },
    {
      "id": "CGAIC-TV-010",
      "title": "Write content digest differs",
      "boundary": "content binding",
      "mutation": "unreviewed content digest supplied",
      "expected": "rejected"
    },
    {
      "id": "CGAIC-TV-011",
      "title": "Command arguments differ",
      "boundary": "command target",
      "mutation": "approved arguments replaced with force push",
      "expected": "rejected"
    },
    {
      "id": "CGAIC-TV-012",
      "title": "Network destination differs",
      "boundary": "network target",
      "mutation": "approved host replaced",
      "expected": "rejected"
    },
    {
      "id": "CGAIC-TV-013",
      "title": "Identical request is replayed",
      "boundary": "request replay",
      "mutation": "same request submitted twice in sequence",
      "expected": "exactly_one_accepted"
    },
    {
      "id": "CGAIC-TV-014",
      "title": "Two requests race for one allowance",
      "boundary": "atomic allowance",
      "mutation": "two distinct requests submitted concurrently",
      "expected": "exactly_one_accepted"
    },
    {
      "id": "CGAIC-TV-015",
      "title": "Timeout after dispatch consumes allowance",
      "boundary": "uncertain outcome",
      "mutation": "downstream throws after invocation begins, then retry attempted",
      "expected": "uncertain_consumed"
    }
  ]
}
