{
  "tool_id": "art-649-publish-model-risk-head",
  "tool_version": "1.0.0",
  "display_name": "Publish Model Risk Head",
  "mcp_name": "publish_model_risk_head",
  "mandate_type": "attestation_mandate",
  "wave": 105,
  "gpu": false,
  "url": "https://ainumbers.co/chaingraph/art-649-publish-model-risk-head.html",
  "description": "Publishes one SPEC.md §HEAD-1 head-commit publication event for a model's revalidation-history stream, so a model's validation history (art-453/art-489 results, or art-562/art-648 lineage artifacts) becomes a sequence-numbered, signer-continuous chain instead of a series of unlinked artifacts a reviewer must independently discover and order, mirroring NAV-LINEAGE-BUILD-SPEC.md §3 and INDEX-LINEAGE-BUILD-SPEC.md §5, applied to a model's revalidation cadence. HARD FENCE: this node never accepts or handles private key material, the caller signs the head-commit off-node via chaingraph/kernels/_head.mjs's own buildHead/signHead and separately runs its own Ed25519 verification (again via _head.mjs's verifyHeadProof/verifyChain) before calling this node. signature_valid and chain_valid are the caller's own verification claim, asserted and digested into this receipt, exactly like art-562's stage-reference citations, never independently re-derived by this node (the real zkVM guest has no WebCrypto at all, so an in-kernel Ed25519 verify result would not be reproducible across this repo's required execution environments). The one field this node DOES independently recompute is head_hash (pure SHA-256/JCS over the caller-supplied head, never trusted as a caller-asserted value, per SO #34). Backed by ocg-head-file@1 only at first, matching the NAV/index lineage rows; a head-file tip proves the signer's claimed tip, it does not itself detect equivocation (needs ocg-head-tlog@1, a later WU) and is not itself a revalidation-cadence enforcement mechanism. The estate's head-commit primitive (SPEC.md §HEAD-1 + _head.mjs) is merged to main; this node applies that estate-internal primitive to a model-risk stream and makes no claim under RDARR, BCBS 239, or SR 26-2 itself.",
  "input_schema_ref": "chaingraph/art-649-publish-model-risk-head.html#manifest",
  "consumes": [
    "art-453-model-validation-status",
    "art-489-model-test-battery",
    "art-562-compile-model-risk-lineage-pack"
  ],
  "feeds": [],
  "status": "live",
  "conformance_fixtures": true,
  "compute_capability": "server",
  "compute_images": [
    {
      "system": "sha256-source",
      "image_id": "sha256:3f1c6d1e5f697c7965be668eb206a5c9d533b097a4d381c90c48aefaafdf0f91",
      "valid_from": "2026-08-17"
    }
  ],
  "export_capability": [
    "json"
  ],
  "standards_basis": "not_applicable",
  "cited_clause_digest": [],
  "compute_proof_ready": "deferred",
  "deferred_reason": "New gpu:false node, art-649-publish-model-risk-head, scaffolded 2026-08-17 (KERNEL-SCAFFOLD-1). No GPU prove has been run and none is proposed by this scaffold — deferred per the section 18 steady-state rule (RIDER-KERNEL.md). Run GPU-CYCLE-PREFLIGHT-1's static pre-screen once compute() is real, then measure user_cycles with runq-cpu exec before booking."
}
