{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "681ece24c9b6d5479114fd42df26bb41385bac35ef4a18b8337b14340961bcf3",
    "authored_runtime_manifest_sha256": "7835bd6d317b2c5ea0a461eee303789420ad1e26192937eda68749b31c650c09",
    "authored_verdict_sha256": "6fb68a0ed697a7b7d8dd37bc1335a50c0f26ad9f47c68fe6e80533afaed640d0",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "An HTTP Set-Cookie header with Domain=github.io followed by a request to attacker.github.io",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "info_leak",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "info_leak",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "HTTP response -> libcurl cookie engine with libpsl -> sibling-domain HTTP request",
  "validated_surface": "api_remote"
}
