{"document":"agent-reserve-review-handoff-manifest","version":"0.1.0","status":"review_handoff_only","scope":"local shadow-ledger reference evidence","independentAudit":false,"certification":false,"productionReady":false,"realValueEnabled":false,"documentedThreats":10,"controls":[{"controlId":"AC01","threatId":"T01","claim":"Invalid or unavailable proof cannot authorize settlement in the reference model.","owner":"fictional-security","evidenceStatus":"reference_tested","evidenceRefs":["/specification.json","/conformance-vectors.json","/verifier-vectors.json"],"residualRisk":"No production signatures, key custody, transport or independent verifier operators exist.","externalGate":"independent cryptographic and verifier review"},{"controlId":"AC02","threatId":"T02","claim":"A receipt settles at most once across modeled local interleavings.","owner":"fictional-engineering","evidenceStatus":"partially_modeled","evidenceRefs":["/conformance-vectors.json","/concurrency-report.json"],"residualRisk":"No persistent database, distributed isolation or network partition test exists.","externalGate":"distributed concurrency implementation and review"},{"controlId":"AC03","threatId":"T03","claim":"Accepted and rejected reference transitions conserve total simulated supply.","owner":"fictional-engineering","evidenceStatus":"reference_tested","evidenceRefs":["/specification.json","/conformance-vectors.json","/threat-model.json"],"residualRisk":"The reference model is not a production ledger.","externalGate":"independent ledger implementation audit"},{"controlId":"AC04","threatId":"T04","claim":"Fictional authority is scoped, expires, rotates, revokes and rejects nonce replay.","owner":"fictional-security","evidenceStatus":"partially_modeled","evidenceRefs":["/identity-spec.json","/identity-vectors.json"],"residualRisk":"No real keys, hardware protection, identity proof or recovery process exists.","externalGate":"production identity and key design"},{"controlId":"AC05","threatId":"T05","claim":"A fictional 3-of-5 quorum fails closed on outage, stale evidence and equivocation.","owner":"fictional-security","evidenceStatus":"partially_modeled","evidenceRefs":["/verifier-spec.json","/verifier-vectors.json"],"residualRisk":"No real signatures, network, incentives, adjudication or independent operators exist.","externalGate":"independent verifier architecture review"},{"controlId":"AC06","threatId":"T06","claim":"Fictional backing gates block modeled undercoverage, illiquidity, concentration and provider outage.","owner":"fictional-governance","evidenceStatus":"partially_modeled","evidenceRefs":["/reserve-spec.json","/reserve-stress.json"],"residualRisk":"No real assets, enforceable redemption, custody, providers, valuation or audit exist.","externalGate":"resource-backing economics and legal enforceability"},{"controlId":"AC07","threatId":"T07","claim":"Fictional collusion gates reject controller overlap, reciprocal loops and artifact reuse.","owner":"fictional-security","evidenceStatus":"partially_modeled","evidenceRefs":["/sybil-policy.json","/sybil-vectors.json"],"residualRisk":"No beneficial-ownership proof, real graph or economic attack-cost evidence exists.","externalGate":"independent Sybil economics review"},{"controlId":"AC08","threatId":"T08","claim":"Deterministic load shedding preserves safety lanes and committed state under modeled overload.","owner":"fictional-engineering","evidenceStatus":"partially_modeled","evidenceRefs":["/load-policy.json","/load-vectors.json"],"residualRisk":"No real capacity, queue, provider-limit, partition or denial-of-service test exists.","externalGate":"production capacity and resilience test"},{"controlId":"AC09","threatId":"T09","claim":"Fictional governance requires delay and independent approval; recovery preserves evidence and supply.","owner":"fictional-governance","evidenceStatus":"partially_modeled","evidenceRefs":["/governance-policy.json","/governance-vectors.json","/incident-policy.json","/incident-vectors.json"],"residualRisk":"No real authority, multisig, enforcement, failover, exercised operators or external audit exists.","externalGate":"real governance and incident-response review"},{"controlId":"AC10","threatId":"T10","claim":"Phase 0 issues no real value and makes no banking, deposit or redemption capability available.","owner":"external-legal-review","evidenceStatus":"blocked_by_design","evidenceRefs":["/protocol.json","/threat-model.json"],"residualRisk":"Legal classification remains unknown in every jurisdiction.","externalGate":"jurisdiction-specific legal analysis"}],"releaseBlockers":["independent security review","formal protocol specification","production identity and key design","distributed concurrency proof","resource-backing economics","jurisdiction-specific legal analysis","real governance and incident response"],"reviewerInstruction":"Reproduce the referenced local evidence, challenge every residual risk, and treat every external gate as unresolved. Structural completeness is not assurance.","structuralVerification":{"passed":12,"failed":0}}