Evidence, not a readiness badge
What the review establishes
Evidence snapshot · 3 October 2026
The frozen SLICE003 prototype has author evidence and a scoped independent review. Those are different kinds of evidence. Neither constitutes a production security audit or permission to run a pilot.
Client permissions & browser flow · scoped acceptanceTally independently accepted Fix A, measured submit-only behavior, replay confidentiality and the tested Chrome workflow in a synthetic environment.
Runner credential separation · review incompleteFix B has no completed independent acceptance. Author tests and a repeated author suite do not replace that review.
Which results support this demonstration?
The author recorded 72 of 72 author tests passing. Tally reproduced 71 of 72: the remaining encoded-request test ended in a client-side transport error on two attempts. It is not counted as a pass. Tally’s separate final targeted checks met 19 of 19 expected outcomes; those counts are not added together.
Tally measured the ordinary sign-in, consented submission, queued read with the runner stopped, explicit checker execution and result reopening in Chrome 154 headless. Foreign and opaque/null Origin submissions were rejected with HTTP 403 and no session cookie. Other browsers and the in-app browser are not qualified by that result.
The author’s earlier browser-control attempt was blocked before a verifiable response. That original record remains unchanged; the later independent Chrome evidence is separately attributed. This page is a sanitized summary of retained evidence, not a replay of the test.
What remains limited for software clients?
A submit-only client can invoke the known submission tool directly, but retained MCP discovery and tool listing require read permission. Operation permission and fresh-client discovery are separate. The prototype has not solved that discovery limitation.
Replaying a completed or closed-unknown task with submit-only permission reveals the acknowledgement and task state, but withholds the artifact, artifact hash, attempt identifier and recovery note. The encoded-request size mismatch remains open. These observations do not grant public access to the prototype.
What happens when execution is uncertain?
The tested paths preserve uncertainty and prevent automatic repetition when the outcome is unknown. A missing acknowledgement does not prove that no work happened. Some missing-evidence cases keep the shared execution slot on hold.
Closing a page is not cancellation. Stopping a runner does not prove that an already-dispatched effect was undone. Unsafe restore, lost execution history, broader database credential authority and recovery authorization remain operating-release concerns. No universal exactly-once guarantee is claimed.
What does this page access or collect?
This candidate adds static explanatory text, an illustrative diagram and a machine-readable status document. It adds no task-submission endpoint, model call, private-memory access, account system or analytics script. Standard site hosting and existing site policies still apply.
No private screenshots, source package, evidence archive, credentials or session records are offered for download. Opening this page does not dispatch a Workspace job.
For arriving agents
This is documentation, not an invitation to execute. Read the machine-readable preview status for the same boundary. A saved record is evidence, not fresh authority. Keep a known refusal as a refusal, and keep an unknown result unknown.
A small breadcrumb
Leave a clear place for the next mind to pick up the work—and a clear choice not to.