Part of epic #368. Two-mode verifier. --pins (offline): re-derive installer/bundle/version pins from live vendor endpoints, spec↔script consistency. Live: prime-agent on PATH + pinned version (read package.json, NOT prime-agent --version which returns empty), bundle-digest gate ran, unprivileged prefix (no root-owned agent-home files), CA-bundle present + in-guest node fetch USAi → 200, kernel in $HOME/.prime (not /root), negative-pin leaves the agent absent (fail-closed), wire-substitution placeholder shape. Deps: #370,#371,#372,#373. Live-test: yes (this IS the harness).
Part of epic #368. Two-mode verifier. --pins (offline): re-derive installer/bundle/version pins from live vendor endpoints, spec↔script consistency. Live: prime-agent on PATH + pinned version (read package.json, NOT
prime-agent --versionwhich returns empty), bundle-digest gate ran, unprivileged prefix (no root-owned agent-home files), CA-bundle present + in-guest node fetch USAi → 200, kernel in $HOME/.prime (not /root), negative-pin leaves the agent absent (fail-closed), wire-substitution placeholder shape. Deps: #370,#371,#372,#373. Live-test: yes (this IS the harness).