← Files VeraARCHIVED FILE

privacy/workstreams/deep-research-validator.json

8.7 KB · Oct 2, 2026 · 00:29 UTC

↓ Download file

{
  "schema_version": 3,
  "workstream": "deep-research-validator",
  "display_name": "Answer Validator",
  "role": "workflow",
  "governed_paths": [
    "skills",
    "scripts",
    "mcp",
    "assets/review-workbench-adapter.json",
    "assets/deep-research-review-widget.html"
  ],
  "governed_shared_paths": [
    "vendor/modules/vera_assurance"
  ],
  "runtime_profiles": [
    "openai-codex",
    "anthropic-cowork"
  ],
  "model_context": {
    "policy": "real_case_data_may_enter_selected_runtime_model_context",
    "classes": [
      {
        "id": "report-and-source-review",
        "purpose": "Assess answer-contract conformance, claim coverage, source identity, semantic support, reasoning quality, professional-judgment boundaries, and proposed corrections",
        "content": "Generated or supplied answer, including a Deep Research report, memo, or one-page letter; answer contract; claims and surrounding text; citations; normalized captured text from fetched public pages or local source files, including extracted PDF page text and page-coverage status, and HTML text parsed without tag attributes, comments, scripts or styles; source-identity, semantic-support, reasoning, issue-treatment, disposition, and professional-judgment assessments; diagnostics; proposed corrections and review decisions. The canonical review record keeps each claim or scope assessment once and uses local references for mechanical observations and the complete audit rather than duplicating those records in each review item.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      },
      {
        "id": "opposing-position-and-comparison",
        "purpose": "Develop and review a substantive opposing case independently of the original validation outcome and compare both positions",
        "content": "Only when the contracted adversarial policy is required for a concrete opinion or an explicit opposing-opinion request. Informational research alone does not create this phase. Complete reviewed original opinion, material case facts, original answer contract, sources and validation limits; actual research queries and selected public source texts; complete opposing opinion or reasoned negative or evidence-limited result; source, support, reasoning and professional-judgment reviews; search record, comparison and its semantic review. The same selected model runtime may perform every phase. Local code hashes phase files and checks structure and declared states; it does not generate legal arguments or choose an outcome.",
        "runtime_profiles": [
          "openai-codex",
          "anthropic-cowork"
        ]
      }
    ]
  },
  "external_boundaries": [
    {
      "id": "cited-url-fetch",
      "kind": "public_research",
      "destination": "Public hosts named by URLs cited in the answer",
      "purpose": "Retrieve cited source pages for claim-support review",
      "content": "Each complete cited HTTP or HTTPS URL, request metadata, and the resulting public page response",
      "optional": false,
      "requires_confirmation": false,
      "runtime_profiles": [
        "openai-codex",
        "anthropic-cowork"
      ],
      "controls": [
        "Fetch only URLs extracted from the supplied answer inventory.",
        "Read at most 1,000,001 response bytes per URL to detect truncation, retain at most the first 1,000,000 bytes, and use a bounded timeout.",
        "Persist normalized captured text only in the private run output so exact-passage observations can be scoped to the specifically cited source.",
        "Use --no-fetch and local source files when network retrieval is unavailable or inappropriate."
      ]
    },
    {
      "id": "opposing-case-research",
      "kind": "public_research",
      "destination": "Public official and reliable-source websites selected for the opposing case",
      "purpose": "When adversarial_policy is required, investigate competing authorities, interpretations, exceptions and factual premises beyond the original citations when needed",
      "content": "Model-selected issue queries, material case facts when required by the research purpose, public URLs and retrieved source text",
      "optional": false,
      "requires_confirmation": false,
      "runtime_profiles": [
        "openai-codex",
        "anthropic-cowork"
      ],
      "controls": [
        "Use current host research capabilities and preserve actual queries, source identities, source captures and access limits.",
        "The opinion helper has no network or model API client; cited-URL acquisition uses the existing validator route."
      ]
    }
  ],
  "security_controls": [
    {
      "id": "private-output-root",
      "control": "Document inspection, source inspection, and packaging require a digest-valid Studio Archive deep-research-validator context, accept local evidence only from that engagement, and write only to the context's run output root or a descendant."
    },
    {
      "id": "public-url-boundary",
      "control": "Initial and redirected HTTP/S URLs are restricted to standard ports without URL credentials. The connection resolves and validates every candidate address immediately before connecting directly to a checked numeric socket address; non-public addresses are rejected. TLS retains the original hostname for certificate validation and SNI. Environment proxies are disabled for this public-source route."
    },
    {
      "id": "hash-bound-canonical-review",
      "control": "final_artifacts.json binds the canonical review_payload.json with SHA-256. In Codex or Cowork, when local MCP is callable, validation can reload that regular local file through the managed run reference and issue a random, in-memory, four-hour token, so render/save/apply do not require the complete payload to be resent at every step. Without local MCP, both runtimes consume the same canonical local review records and keep decisions pending unless persisted artifacts prove save and apply; unmanaged or legacy runs may still use an inline payload."
    },
    {
      "id": "content-addressed-source-captures",
      "control": "Normalized source captures with identical SHA-256 content reuse one canonical local text file. Every source record, URL, retrieval result, and duplicate-content alias remains in source_inventory.json so provenance and professional source review are preserved."
    },
    {
      "id": "local-review-output-download",
      "control": "The local review server requires the session token for output downloads. It accepts only files declared by the local run, within its output directory, rejects symlinks and traversal, and limits downloads to 50 MB. Files are downloaded as opaque bytes; HTML is not executed in the review origin. This does not claim atomic protection from concurrent filesystem changes. The browser may retain a user-requested downloaded copy; this route does not send document content to the model or an external service."
    },
    {
      "id": "exact-opinion-pair-binding",
      "control": "The opinion CLI requires the existing deep-research-validator Studio Archive context. Fixed phase directories stay beneath its output root; traversal and symlink artifacts are rejected. Preparation binds every original phase file; delivery binds both packages and the comparison. Verification rejects changed, missing or newly added phase files and recomputes both validation records. Hashes establish local integrity, not provider attestation or legal correctness."
    },
    {
      "id": "local-browser-private-review-payload",
      "control": "The local review server requests component-only private review metadata only for the registered render tool. The browser receives that payload locally; normal MCP callers continue to receive structuredContent. This is transport separation, not anonymization of data selected for model review. Reload restores the persisted applied decisions for the same plugin and run through the existing browser path sanitization. It does not apply decisions again or change the external routes. Read-only local rendering accepts validated running, review-ready and completed contexts; Save/Apply still require a running context. Nested result folders resolve the owning portable run and validate the exact requested descendant before rendering. Archived views also show a localized read-only notice and disable Save/Apply; server-side write validation remains authoritative."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-28",
    "reviewed_by": "privacy-surface-review",
    "basis": "external_boundary_review_of_workflow_source",
    "source_fingerprint": "cfcb1274a02a96f1ad2fea671d271ffe05f1b99a8879e847e1c1a9fe2f0ea262"
  },
  "governed_repository_paths": [
    "plugins/vera/skills/quesito-legale-fiscale/SKILL.md",
    "plugins/vera/skills/adversarial-opinion/SKILL.md"
  ]
}

SHA-256: afcd3760f886abb3cca8ba619c5a11f251225cee3d265f09f27733af6136fc63