{
  "tool_id": "art-424-witness-cosignature-verifier",
  "kernel_id": "art-424-witness-cosignature-verifier",
  "display_name": "Witness Cosignature Verifier",
  "tool_version": "1.0.0",
  "mandate_type": "cryptographic_mandate",
  "purpose": "Verifies a C2SP tlog-checkpoint + witness-cosignature note (SPEC.md §20.2) offline: confirms the note's origin and root match a §20/§20.1 batch anchor's declared anchored_hash, then checks each pinned witness's cosignature against a k-of-n threshold. Supports both Ed25519 cosignature/v1 and ML-DSA-44 (the suite §20.2 names alongside it under the §PQC-1 reserved-extension discipline). Consumes a caller-supplied checkpoint note (e.g. from a c2sp.org/tlog-proof bundle), verify-side only, zero log operation, zero network fetch. Golden fixtures dogfood the tool's own output, including a tampered negative fixture that must fail. States only that ≥k pinned witnesses signed this root; does not establish log honesty, key ownership, or leaf inclusion (see art-280/art-279 and SPEC.md §20.1 for those checks).",
  "control_description": "Verifies a C2SP tlog-checkpoint + witness-cosignature note (SPEC.md §20.2) offline: confirms the note's origin and root match a §20/§20.1 batch anchor's declared anchored_hash, then checks each pinned witness's cosignature against a k-of-n threshold. Supports both Ed25519 cosignature/v1 and ML-DSA-44 (the suite §20.2 names alongside it under the §PQC-1 reserved-extension discipline). Consumes a caller-supplied checkpoint note (e.g. from a c2sp.org/tlog-proof bundle), verify-side only, zero log operation, zero network fetch. Golden fixtures dogfood the tool's own output, including a tampered negative fixture that must fail. States only that ≥k pinned witnesses signed this root; does not establish log honesty, key ownership, or leaf inclusion (see art-280/art-279 and SPEC.md §20.1 for those checks).",
  "declared_inputs": [],
  "declared_outputs": [],
  "kernel_digest": "sha256:d9ed5d3a0780e192b9d8f56ff41b6893ab74c516128dfca643191e9a76324caf",
  "trust_label": "independently verified: zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-07-10",
  "last_validated": "2026-07-10",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 50,
  "source_url": "https://ainumbers.co/chaingraph/art-424-witness-cosignature-verifier.html",
  "generated_at": "2026-08-15T11:12:17.704Z"
}
