{
  "stage": "stage4-certify",
  "generated_at": "2026-03-28T21:00:04.537Z",
  "duration_ms": 5309,
  "trust_score": {
    "score": 68,
    "grade": "D",
    "maturity": "Initial",
    "max_achievable": 100,
    "signals": [
      {
        "signal": "security_scan",
        "score": 1,
        "weight": 0.15,
        "contribution": 0.15,
        "source": "stage2b-security",
        "rationale": "No security findings"
      },
      {
        "signal": "supply_chain",
        "score": 1,
        "weight": 0.1,
        "contribution": 0.1,
        "source": "stage2a-sbom",
        "rationale": "Skills have no dependency tree — supply chain N/A, scored as clean"
      },
      {
        "signal": "adversarial",
        "score": 0.98,
        "weight": 0.25,
        "contribution": 0.245,
        "source": "stage3b-adversarial",
        "rationale": "1 finding(s): 1 review (-2%)"
      },
      {
        "signal": "provenance",
        "score": 0.8,
        "weight": 0.2,
        "contribution": 0.16,
        "source": "stage1-ingest",
        "rationale": "source hash present, publisher identified, build succeeded, extraction method: llm_assisted"
      },
      {
        "signal": "consumer_confirm",
        "score": 0,
        "weight": 0.1,
        "contribution": 0,
        "source": "stage3a-functional",
        "rationale": "Pipeline-derived baseline: 0/5 triggers activated (no external reports yet)"
      },
      {
        "signal": "behavioral_pass",
        "score": 0,
        "weight": 0.1,
        "contribution": 0,
        "source": "stage3a-functional",
        "rationale": "0/5 triggers activated (0.0%)"
      },
      {
        "signal": "contract_accuracy",
        "score": 1,
        "weight": 0.06,
        "contribution": 0.06,
        "source": "stage3a-functional",
        "rationale": "3/3 negative tests passed (100.0%)"
      },
      {
        "signal": "uptime",
        "score": 1,
        "weight": 0.04,
        "contribution": 0.04,
        "source": "pipeline-derived",
        "rationale": "Static instruction text — uptime N/A, scored as available"
      }
    ],
    "utility_multiplier": 0.9,
    "methodology_version": "2.1"
  },
  "review_flags": {
    "total": 6,
    "blocking": 0,
    "flags": [
      {
        "category": "security",
        "severity": "high",
        "source": "stage3b-adversarial",
        "description": "Adversarial finding (prompt_injection_chains): Several skills reference user-provided content (files, messages, data) without explicit data-boundary markers. The git-commit-conventional skill processes git diffs and user requests, the create-pull-request skill analyzes branch changes, and the mastra-api skill processes agent IDs and workflow names from user input. While these skills appear to treat user content as data within their scope, the lack of explicit data boundaries could potentially allow instruction-like user content to influence skill behavior.",
        "blocks_certification": false,
        "kind": "finding"
      },
      {
        "category": "content",
        "severity": "medium",
        "source": "stage4-assembler",
        "description": "Description section was synthesized by LLM from stage data — verify accuracy",
        "blocks_certification": false,
        "kind": "note"
      },
      {
        "category": "publisher",
        "severity": "medium",
        "source": "stage1-ingest",
        "description": "Publisher \"liatrio-labs\" is not verified — first certification from this publisher",
        "blocks_certification": false,
        "kind": "note"
      },
      {
        "category": "provenance",
        "severity": "low",
        "source": "stage1-provenance",
        "description": "Single contributor — no peer review evidence in commit history",
        "blocks_certification": false,
        "kind": "note"
      },
      {
        "category": "provenance",
        "severity": "low",
        "source": "stage1-provenance",
        "description": "Repository is 19 days old — recently created",
        "blocks_certification": false,
        "kind": "note"
      },
      {
        "category": "provenance",
        "severity": "low",
        "source": "stage1-provenance",
        "description": "Package description appears to be boilerplate or template text",
        "blocks_certification": false,
        "kind": "note"
      }
    ]
  },
  "signing": {
    "content_hash": "sha256:3f9d5b86eb9d12be9b91ab3da5394f40aa5fd40f530ea8ab8829eae0dae8bd59",
    "certified_at": "2026-03-28T21:00:04.183Z",
    "expires_at": "2027-03-28T21:00:04.183Z",
    "key_id": "kms-9db4ed3b9f53",
    "artifact_path": "C:\\Users\\scott\\Desktop\\Projects\\contract-pipeline\\pipeline\\data\\capabilities\\liatrio-agents-md\\liatrio-agents-md-latest.cert.json"
  },
  "assembly": {
    "capability_type": "skill",
    "description_source": "llm_generated",
    "completed_stages": [
      "stage1-ingest",
      "stage2b-security",
      "stage3a-functional",
      "stage3b-adversarial",
      "stage3c-fingerprint"
    ],
    "failed_stages": [],
    "skipped_stages": [
      "stage2a-sbom"
    ]
  }
}