Skip to content

prime-agent kit: scripts/verify (pins + live assertions) #374

Description

@wz-gsa

Part of epic #368. Two-mode verifier. --pins (offline): re-derive installer/bundle/version pins from live vendor endpoints, spec↔script consistency. Live: prime-agent on PATH + pinned version (read package.json, NOT prime-agent --version which returns empty), bundle-digest gate ran, unprivileged prefix (no root-owned agent-home files), CA-bundle present + in-guest node fetch USAi → 200, kernel in $HOME/.prime (not /root), negative-pin leaves the agent absent (fail-closed), wire-substitution placeholder shape. Deps: #370,#371,#372,#373. Live-test: yes (this IS the harness).

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestvalidationSchema, linting, tests, CI validation

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions