A maximal claim list under an untrusted key
This envelope claims everything: mediated, transparency-log inclusion, and complete mediation under a real Ed25519 signature. But the signing key is not in the trust file, so the signature is unknown_key, the assertion is unsigned, and not one claim verifies. It sounds strong. It proves nothing.
assertion_signed: false · verified_claims: none
This is a fixture from the public Evidence Theater kill suite. Its appraisal is reproducible with the AARP verifier:
pipelock-verifier aarp k02-untrusted-issuer-overclaim.aarp.json --trust killsuite-trust.json --json- k02-untrusted-issuer-overclaim.aarp.json: the envelope
- appraisal.json: the appraisal a correct verifier must emit
- expect.json: the attack class and what must not verify
- killsuite-trust.json: the pinned test trust