What it does for you: It runs one small Node.js program against read-only copies of the files it is given, inside a macOS sandbox with no network, no writable path and no child processes. Then it reports exactly what it saw: whether the program was allowed to start, how it ended, and what it printed. It does not judge the result.

Plate 2, position 1, Plumb under glass: a tiny gear under a glass cloche. The plate is shown whole.
How it links: It takes a pinned program and input files, such as an exported Candidate from Repository sealing / export, and gives observed process facts back to its caller. Only the Repository collector calls it, and nothing calls that collector yet: no Execution Run or Guarded verification uses the executor. One test proves a Repository export runs in it.
Honest limits:
- It was proven only on this Mac: macOS on arm64 with Node 26.8.1 and
/usr/bin/sandbox-exec. Another platform, chip or Node version is refused, never run unsandboxed. Another Mac that passes those checks can run it, but that Mac is not proven. - It asks the kernel to kill a program that runs past its time limit (at most five minutes), is cancelled, prints too much, or reports start-up limits that differ from the request. That is a request, not a deadline: an unconfirmed kill is reported as unresolved, not finished. Other start-up failures can end without a kill request; the result records admission as refused, absent or malformed. There is no hard memory, disk or CPU-time stop.
- If the controlling process dies, the program is not stopped, and its slot stays taken until someone cleans it up by hand.
- What the program prints carries no authority. Only what the host observed counts.
Status: Accepted for the tested stateless macOS boundary (local review, 28 September 2026). This is local infrastructure only, not a release, a Verdict or a customer benefit. All 27 epics remain open.
