Bare agent
Loading recording...
SSRF / internal target
A reach for the cloud metadata endpoint is blocked by the SSRF layer.
Loading recording...
Loading recording...
Timeline
The transcript is playback metadata. The receipts below come from the signed chain.
{}Verify the signed decision chain in the packet:
pipelock-verifier audit-packet . --key ...Or appraise the assurance envelope and reproduce the panel below:
pipelock-verifier aarp assurance.json --trust ../appraiser-trust.json --jsonAssurance appraisal
This panel renders the AARP v0.1 appraisal generated for a lab-signed assurance envelope built for this scenario. The appraiser never returns “trusted” or “safe.” It confirms only the narrow facts a signature mechanically supports, and it leads with what it refuses to assert. That applies to a valid Pipelock receipt as readily as to a forged one. assurance.json · appraisal.json · appraiser-trust.json
Loading appraisal…
No matter how strong the signature, this appraisal never proves any of these:
Properties a reader might wrongly read into the evidence that is present:
The envelope claimed these, but the evidence does not support them, so they stay unverified:
Scope
Loading completeness note...