{
  "stage": "stage4-certify",
  "generated_at": "2026-03-29T17:53:58.451Z",
  "duration_ms": 5997,
  "trust_score": {
    "score": 97,
    "grade": "A",
    "maturity": "Initial",
    "max_achievable": 100,
    "signals": [
      {
        "signal": "security_scan",
        "score": 1,
        "weight": 0.15,
        "contribution": 0.15,
        "source": "stage2b-security",
        "rationale": "No security findings"
      },
      {
        "signal": "supply_chain",
        "score": 1,
        "weight": 0.1,
        "contribution": 0.1,
        "source": "stage2a-sbom",
        "rationale": "Clean supply chain (101 components, 0 vulnerabilities)"
      },
      {
        "signal": "adversarial",
        "score": 1,
        "weight": 0.25,
        "contribution": 0.25,
        "source": "stage3b-adversarial",
        "rationale": "No adversarial findings — clean"
      },
      {
        "signal": "provenance",
        "score": 1,
        "weight": 0.2,
        "contribution": 0.2,
        "source": "stage1-ingest",
        "rationale": "source hash present, publisher identified, build succeeded, live MCP enumeration"
      },
      {
        "signal": "consumer_confirm",
        "score": 0.913,
        "weight": 0.1,
        "contribution": 0.09132947976878614,
        "source": "stage3a-functional",
        "rationale": "Pipeline-derived baseline: 91.3% functional pass rate (no external reports yet)"
      },
      {
        "signal": "behavioral_pass",
        "score": 0.913,
        "weight": 0.1,
        "contribution": 0.09132947976878614,
        "source": "stage3a-functional",
        "rationale": "91.3% of functional tests passed"
      },
      {
        "signal": "contract_accuracy",
        "score": 1,
        "weight": 0.06,
        "contribution": 0.06,
        "source": "stage3a-functional",
        "rationale": "Avg contract accuracy across 7 tools: 100.0%"
      },
      {
        "signal": "uptime",
        "score": 1,
        "weight": 0.04,
        "contribution": 0.04,
        "source": "pipeline-derived",
        "rationale": "Server responded throughout pipeline testing — baseline uptime 100% (no monitoring data yet)"
      }
    ],
    "utility_multiplier": 0.991,
    "methodology_version": "2.1"
  },
  "review_flags": {
    "total": 7,
    "blocking": 0,
    "flags": [
      {
        "category": "content",
        "severity": "medium",
        "source": "stage4-assembler",
        "description": "Description section was synthesized by LLM from stage data — verify accuracy",
        "blocks_certification": false,
        "kind": "note"
      },
      {
        "category": "content",
        "severity": "medium",
        "source": "stage4-assembler",
        "description": "Behavioral guarantees derived from README — verify accuracy against observed behavior",
        "blocks_certification": false,
        "kind": "note"
      },
      {
        "category": "publisher",
        "severity": "medium",
        "source": "stage1-ingest",
        "description": "Publisher \"Fidensa (https://fidensa.com)\" is not verified — first certification from this publisher",
        "blocks_certification": false,
        "kind": "note"
      },
      {
        "category": "provenance",
        "severity": "medium",
        "source": "stage1-provenance",
        "description": "No license file found in repository",
        "blocks_certification": false,
        "kind": "note"
      },
      {
        "category": "provenance",
        "severity": "low",
        "source": "stage1-provenance",
        "description": "No SECURITY.md or SECURITY.txt file found — no published vulnerability reporting process",
        "blocks_certification": false,
        "kind": "note"
      },
      {
        "category": "provenance",
        "severity": "low",
        "source": "stage1-provenance",
        "description": "Single contributor — no peer review evidence in commit history",
        "blocks_certification": false,
        "kind": "note"
      },
      {
        "category": "provenance",
        "severity": "low",
        "source": "stage1-provenance",
        "description": "Repository is 0 days old — recently created",
        "blocks_certification": false,
        "kind": "note"
      }
    ]
  },
  "signing": {
    "content_hash": "sha256:6f79da81604e74bf9fc0326cf8ea857e4980c1127368a43c597b3acd1e153cbd",
    "certified_at": "2026-03-29T17:53:58.096Z",
    "expires_at": "2027-03-29T17:53:58.096Z",
    "key_id": "kms-9db4ed3b9f53",
    "artifact_path": "C:\\Users\\scott\\Desktop\\Projects\\contract-pipeline\\pipeline\\data\\capabilities\\fidensa-mcp-server\\fidensa-mcp-server-0.4.1.cert.json"
  },
  "assembly": {
    "capability_type": "mcp_server",
    "description_source": "llm_generated",
    "completed_stages": [
      "stage1-ingest",
      "stage2a-sbom",
      "stage2b-security",
      "stage3a-functional",
      "stage3b-adversarial",
      "stage3c-fingerprint"
    ],
    "failed_stages": [],
    "skipped_stages": []
  }
}