{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "7d92370c3b36ccb8a5fa156a5d6df57af66adce9f80f35b27bd5a2b719876e5b",
    "authored_runtime_manifest_sha256": "2f0e1a215aa9f3c7e912e867ef80f9f971fa2dda6c12c0dd036520970e24a5bd",
    "authored_verdict_sha256": "cfbc10cb2b16d9a37a5abc32866bdd2b0f05364732a9863b7c1815070d948cc2",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "HTTP pathname /%2e%2e/private-sentinel.txt sent with URL normalization disabled",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "info_leak",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "info_leak",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "Node HTTP listener -> h3 event URL -> serveStatic -> getMeta/getContents filesystem callbacks",
  "validated_surface": "api_remote"
}
