{
  "markdown": "# LiquiLens Evidence Carrier\n\n[![CI](https://github.com/beepboop2025/liquilens-evidence-carrier/actions/workflows/ci.yml/badge.svg)](https://github.com/beepboop2025/liquilens-evidence-carrier/actions/workflows/ci.yml)\n[![Release](https://img.shields.io/github/v/release/beepboop2025/liquilens-evidence-carrier)](https://github.com/beepboop2025/liquilens-evidence-carrier/releases)\n[![License](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](LICENSE)\n\nLiquiLens Evidence Carrier is a transport-neutral contract for moving financial\nevidence through files, warehouses, event buses, observability systems, data\ncatalogs, FDC3 desktops, notebooks, citations, and AI agents without dropping\nprovenance, rights, freshness, or authority boundaries.\n\nThe carrier is infrastructure for inspection and reproducibility. It is not an\norder, recommendation, credit rating, market-data entitlement, or endorsement\nby Bloomberg, LSEG, FactSet, FINOS, or any other platform.\n\nThe current signed and published core release is `v0.19.0`. Annotated tag\nobject `c3239bfc7c4d3c4b7fc5ce26e0f602962e7d4337` targets the allowlisted\nSSH-signed release commit `8f5738c9e77cc95b9a68543d478b9521f5595d61`, tree\n`acca6fa7aab75ebc91bf044e153c6468cd6f9c0c`; remote `main` resolved to the\nsame commit when the receipt was verified. The exact commit passed\n[preflight run 33630656569](https://github.com/beepboop2025/liquilens-evidence-carrier/actions/runs/33630656569),\nand [release run 33630790150](https://github.com/beepboop2025/liquilens-evidence-carrier/actions/runs/33630790150)\npublished 23 assets at `2026-09-02T12:36:19Z`. All 22 entries in the downloaded\n`SHA256SUMS` passed; its SHA-256 is\n`c6d52cbf8794db6e478e3b2ea9e1ed8eee7757137650892a6a96fcbb839bb6bc`.\n[Attestation 44695012](https://github.com/beepboop2025/liquilens-evidence-carrier/attestations/44695012)\nbinds the 22 non-manifest artifacts to the tagged source. The official MCP\nRegistry record is active/latest at 0.19.0 and pins MCPB SHA-256\n`11db11aefafcc6c4ba558877d1f9892fc708150b3afbaa28a741e74435b9a91a`.\n\nRelease `v0.19.0` preserves every Trade Safety v1 schema byte and adds the\ndeterministic adversarial corpus, dependency-free TypeScript-compatible Node\nraw-UTF8 verifier and authenticated paper-only order guard, OpenBB 0.2.0\nhash-only verification, and MCP corpus discovery. Gateway 0.1.2 pins core\n0.19.0 and remains a read-only, hash-only sandbox with no broker route.\n[Container run 33630789998](https://github.com/beepboop2025/liquilens-evidence-carrier/actions/runs/33630789998)\npublished and smoke-tested the core multi-platform index at\n`sha256:bdbfed2afa87f25e8ef88dffeb4ba7ab198854705528c0de5abe31552a170b9a`;\n[attestation 44695462](https://github.com/beepboop2025/liquilens-evidence-carrier/attestations/44695462)\nbinds that digest to the tagged source. Separately,\n[gateway run 33630790011](https://github.com/beepboop2025/liquilens-evidence-carrier/actions/runs/33630790011)\npublished and smoke-tested gateway index\n`sha256:b5c43013da1fdddd9e6e56cab0e4f0f562e39ab25cc640869c5008e3457218e3`;\n[attestation 44695195](https://github.com/beepboop2025/liquilens-evidence-carrier/attestations/44695195)\nbinds it to the same commit. These are package and registry artifacts, not a\nhosted gateway, live-order activation, or financial authority.\n\nA later independent gateway-only publication used signed annotated tag\n`trade-safety-gateway-v0.1.3`, tag object\n`757c18928c8036910ab50c80ec073679d7434abf`, targeting signed commit\n`fa8e25ae8e0e992611706b8d66e951342d594243` and tree\n`7680694bf3397a0844f2388fb29067ff402f066d`.\n[Gateway run 33651560380](https://github.com/beepboop2025/liquilens-evidence-carrier/actions/runs/33651560380)\npublished and smoke-tested the amd64/arm64 index\n`sha256:9b8f704547ecf6c43039b34149d6cca842de5d66cba13c040199cf5f3f216d61`;\n[attestation 44751184](https://github.com/beepboop2025/liquilens-evidence-carrier/attestations/44751184)\nbinds that digest to the tagged source. The run recorded semantic,\nsource-commit, and signed-tag-object aliases without moving `latest` or a\n`core-*` alias. There is no corresponding GitHub Release object and no hosted\ndeployment or paid-route activation is claimed. See the exact\n[`gateway 0.1.3 publication receipt`](docs/RELEASE-TRADE-SAFETY-GATEWAY-0.1.3.md).\n\nSee [`docs/RELEASE-0.19.0.md`](docs/RELEASE-0.19.0.md) for the complete release,\nRegistry, artifact, and OCI receipt. GitHub reports the Release record itself as\n`immutable: false`; version-tag ruleset `21288366` blocks `v*` tag update and\ndeletion with no bypass, and the current assets are checksum- and\ntransparency-attested, but they are not described as platform-enforced\nimmutable assets. The complete historical v0.18.0 receipt remains\n[`docs/RELEASE-0.18.0.md`](docs/RELEASE-0.18.0.md).\n\nThe immutable annotated `v0.17.0` tag object\n`cb85e527c2b74abf476fd9a01b73b2235ce976b7` targets protected-main merge\n`edde9b92ad9851d2974b91326a8c3877f4386d3a`, but its\n[release run 33585764285](https://github.com/beepboop2025/liquilens-evidence-carrier/actions/runs/33585764285)\nfailed at the commit-signature gate before any artifact was built, attested, or\npublished. There is no v0.17.0 GitHub release or official MCP Registry record.\nSee [`docs/RELEASE-0.17.1.md`](docs/RELEASE-0.17.1.md) for the unchanged recovery\nreceipt and [`docs/RELEASE-0.17.0.md`](docs/RELEASE-0.17.0.md) for the unchanged\nfailed-attempt record.\n\n## Why it travels\n\nOne verified JSON object can be embedded in:\n\n- FDC3 contexts and app-directory workflows;\n- CloudEvents and OpenTelemetry logs;\n- OpenLineage custom facets and data catalogs;\n- Arrow or Parquet schema metadata;\n- dbt warehouse tests, CSV, SQL, and spreadsheets;\n- CSL-JSON citations and PROV-O knowledge graphs; and\n- MCP or other agent responses.\n\nEvery full carrier preserves `event_time <= knowledge_time <= as_of`, source\nhashes, explicit redistribution rights, a content-derived identity, and an\nall-false execution/recommendation/credit-rating boundary. Restricted or\nunknown rights fail closed; incomplete or expired evidence is redacted to a\nseparately identified reference rather than silently upgraded.\n\n## Install and verify\n\nWant to inspect an explained copilot decision first? The\n[offline copilot demo](integrations/trading-copilot/README.md#try-an-offline-decision-first)\nruns from this source checkout with Python alone. It uses clearly synthetic inputs,\nshows candidate and HOLD scenarios, and keeps execution blocked without network,\ncredentials or broker setup. It is separate from the signed core package below.\n\nThe [installation guide](docs/INSTALLATION.md) covers ordinary conda-forge\n`0.15.0`, the listed Dev Container Feature (Carrier `0.14.0`), and SchemaStore\neditor setup. Those channels have their own versions; use the signed `0.19.0`\nwheel below for the current core release and Trade Safety verification.\n\n```bash\n# Source checkout (main may contain post-release documentation)\nuv sync --locked\nuv run liquilens-evidence --help\n\n# Signed v0.19.0 wheel; checksum verified against the release manifest\npython -m pip install 'https://github.com/beepboop2025/liquilens-evidence-carrier/releases/download/v0.19.0/liquilens_evidence-0.19.0-py3-none-any.whl#sha256=1adccb72376f50456fd16a979e372f802ae73ba35b766633bc3d8bd4ab5abcc8'\nliquilens-evidence issue examples/descriptor.json > carrier.json\nliquilens-evidence verify carrier.json --as-of 2026-08-24T12:00:00Z\nliquilens-evidence convert carrier.json --format fdc3\n```\n\nPublished release `v0.19.0` provides a wheel and checksum manifest. The Python\nruntime has no third-party dependencies. A Node.js verifier is also\nincluded for cross-language `liquilens-hash-tree-v1` identity checks:\n\n```bash\nnode protocol/verify_hash_tree_v1.mjs --artifact evidence-carrier carrier.json\nnode protocol/verify_hash_tree_v1.mjs --artifact fleet-brief fleet-brief.json\nnode protocol/verify_hash_tree_v1.mjs --artifact trade-safety-receipt receipt.json\n```\n\n## Canonical contract identities\n\n| Contract | Canonical identity | Availability at this source checkpoint |\n|---|---|---|\n| Full carrier | `https://liquilens.in/protocol/liquilens-evidence-carrier-v1.schema.json` | Published and hosted |\n| Redacted reference | `https://liquilens.in/protocol/liquilens-evidence-carrier-reference-v1.schema.json` | Published and hosted |\n| Four-product fleet brief | `https://liquilens.in/protocol/liquilens-fleet-brief-v1.schema.json` | Published and hosted |\n| Trade Safety request | `https://liquilens.in/protocol/liquilens-trade-safety-request-v1.schema.json` | Published v0.19.0 release asset and canonically hosted |\n| Trade Safety policy | `https://liquilens.in/protocol/liquilens-trade-safety-policy-v1.schema.json` | Published v0.19.0 release asset and canonically hosted |\n| Broker preview reference | `https://liquilens.in/protocol/liquilens-broker-preview-reference-v1.schema.json` | Published v0.19.0 release asset and canonically hosted |\n| Trade Safety receipt | `https://liquilens.in/protocol/liquilens-trade-safety-receipt-v1.schema.json` | Published v0.19.0 release asset and canonically hosted |\n| FDC3 Trade Safety receipt | `https://liquilens.in/protocol/fdc3/com.liquilens.trade-safety-receipt.schema.json` | Published v0.19.0 release asset and canonically hosted |\n| FDC3 context | `https://liquilens.in/protocol/fdc3/com.liquilens.evidence.schema.json` | Published and hosted |\n| OpenLineage facet | `https://liquilens.in/protocol/openlineage/liquilens-evidence-facet.schema.json` | Published and hosted |\n\nThe five Trade Safety identities above are stable schema `$id` values. LiquiLens\nPages [run 33592149926](https://github.com/beepboop2025/liquilens-site/actions/runs/33592149926)\nsucceeded at 2026-09-02T04:49:12Z for site revision\n`3ec660175c81c5b282715ee400eea2f771dc2610`; its post-deploy gate retrieved all\nfive URLs over HTTPS and matched their exact bytes to the hashes in\n[`protocol/catalog.json`](protocol/catalog.json). This is schema-hosting proof,\nnot a hosted Trade Safety gateway or live-order activation receipt.\n\nThe current contracts are v1. Release `v0.17.1` added Trade Safety without\nchanging the previously published Carrier or Fleet Brief semantics. Release\n`v0.19.0` preserves the v1 schema bytes and extends cross-language verification;\nit does not create a new protocol identity. The signed release workflow is\n[run 33630790150](https://github.com/beepboop2025/liquilens-evidence-carrier/actions/runs/33630790150),\nthe wheel SHA-256 is\n`1adccb72376f50456fd16a979e372f802ae73ba35b766633bc3d8bd4ab5abcc8`, and\nthe MCPB SHA-256 is\n`11db11aefafcc6c4ba558877d1f9892fc708150b3afbaa28a741e74435b9a91a`.\nProduction integrations can pin `v0.19.0`; separately released container,\nskill, plugin, browser, and package-manager channels retain their own verified\nversions. The canonical URLs are now available for public schema discovery.\n\n## Order-bound Trade Safety Receipts\n\n`liquilens.trade-safety-receipt.v1` composes independent Seiche funding/system\ncontext, Undertow position-sized exit context, optional LiquiLens institution\ncontext, an operator-authored policy, and a broker-preview reference into one\nshort-lived receipt bound to one exact proposed order. Missing, stale,\nrestricted, mismatched, or future-dated inputs fail closed.\n\n```bash\nliquilens-evidence issue-trade-safety \\\n  --request examples/trade-safety/request.paper.json \\\n  --evidence examples/trade-safety/evidence.paper.json \\\n  --policy examples/trade-safety/policy.paper.json \\\n  --broker-preview examples/trade-safety/broker-preview.paper.json \\\n  --issuer examples/trade-safety/issuer.paper.json \\\n  --as-of 2026-09-02T12:00:00Z > receipt.json\n\nliquilens-evidence verify-trade-safety receipt.json \\\n  --as-of 2026-09-02T12:00:30Z\n```\n\nA hash-only receipt supports observation and paper conformance. A live `pass`\nrequires tenant-local authenticated integrity, real-money-eligible required\nevidence, an executable Undertow quote, and an unexpired broker preview bound to\nthe same request and account. Current public adapters satisfy none of those live\ngates. A `pass` is not advice, broker approval, or an execution instruction;\nthe immutable authority object keeps execution, recommendation, allocation,\ncredit-rating, and executable-quote authority false. See\n[`docs/TRADE-SAFETY-RECEIPT-V1.md`](docs/TRADE-SAFETY-RECEIPT-V1.md), the\n[`adoption plan`](docs/TRADE-SAFETY-ADOPTION-PLAN.md), and the\n[`read-only sandbox gateway`](integrations/trade-safety-gateway/README.md).\n\nThe gateway `0.2.0` source candidate adds a server-owned policy floor and an\noptional x402 v2/Bazaar access route for AI agents. Payment purchases access to\nthe exact receipt only; it never relaxes policy, changes an outcome, extends\nevidence freshness, or becomes execution authority. x402 is disabled without a\ncomplete operator configuration, and no hosted `0.2.0` activation or paid-use\nclaim is made here. See the [`x402 operating contract`](docs/TRADE-SAFETY-X402.md)\nand [`traction measurement contract`](docs/TRADE-SAFETY-TRACTION.md).\n\nPython broker and agent runtimes can place the fail-closed, paper-only\n[`before_order` guard](docs/TRADE-SAFETY-ORDER-GUARD.md) around their only\nsubmit callable. Its agent-facing gateway requires tenant-authenticated HMAC\nreceipts, so a missing, expired, mismatched, cross-account, or non-pass receipt\nnever reaches broker code. A configured claim store blocks receipt replay; use a\ndurable operator-owned store outside local paper/demo runs. Live submission\nremains held until the broker idempotency and uncertain-outcome reconciliation\ngates are complete.\n\nTypeScript and Node consumers can use the zero-runtime-dependency\n[`@liquilens/trade-safety` package](integrations/typescript/README.md). Its\nauthoritative APIs consume raw UTF-8 bytes so `1000` and `1000.0` retain their\ndifferent protocol identities, and it rejects malformed UTF-8, duplicate keys,\ntamper, cross-context use, expiry, replay, and every live request before the\npaper submit callback. The committed corpus and threat model are documented in\n[`TRADE-SAFETY-CONFORMANCE.md`](docs/TRADE-SAFETY-CONFORMANCE.md).\n\n## Four-product fleet briefs\n\n`liquilens.fleet-brief.v1` bundles already-issued native carriers without\nflattening LiquiLens, Seiche, Undertow, and Palimpsest into one score. Each brief\ncontains exactly one rights-aware section per product and explicitly preserves\n`full`, `metadata_only`, `unavailable`, `rejected`, or `missing` state.\n\n```bash\nliquilens-evidence issue-brief \\\n  --liquilens ./liquilens.carrier.json \\\n  --seiche ./seiche.carrier.json \\\n  --undertow ./undertow.carrier.json \\\n  --palimpsest ./palimpsest.carrier.json \\\n  --as-of 2026-08-25T00:00:00Z > fleet-brief.json\n\nliquilens-evidence verify-brief fleet-brief.json \\\n  --as-of 2026-08-25T00:00:00Z\n```\n\nIssuance performs no discovery or network fetch. A product mismatch, duplicate,\nunknown field, or tampered carrier fails closed. Rejected rights never disclose\nsource metadata or payload. See\n[`docs/FLEET-BRIEF-V1.md`](docs/FLEET-BRIEF-V1.md) for the complete contract.\n\n## Offline MCP server\n\nThe package includes a zero-third-party-dependency stdio server for agents that\nneed to inspect local carrier JSON. It implements current stateless MCP\n`2026-07-28` (including `server/discover`) and the latest initialization-based\nrevision, `2025-11-25`, for existing clients.\n\n```json\n{\n  \"mcpServers\": {\n    \"liquilens-evidence-carrier\": {\n      \"command\": \"liquilens-evidence-mcp\",\n      \"args\": [\"--root\", \"/absolute/path/to/evidence\"]\n    }\n  }\n}\n```\n\nThe published `v0.19.0` release exposes four read-only tools:\n\n- `verify_carrier` verifies the content identity, clocks, rights, and export\n  disposition of one explicit JSON path below the configured root.\n- `project_carrier` applies an existing rights-aware projection (`fdc3`,\n  `cloudevent`, `otel`, `openlineage`, `jsonld`, `csl`, `flat`, or `arrow`).\n- `verify_fleet_brief` verifies one local four-product brief at its exact\n  recorded evaluation clock without returning embedded evidence bodies.\n- `verify_trade_safety_receipt` verifies one local hash-only order-bound receipt.\n  It accepts no secret; HMAC/live receipts fail closed and must be verified\n  inside the tenant boundary.\n\nIt never fetches network data, expands restricted rights, recommends, rates\ncredit, or executes a financial action. The published `v0.19.0` GitHub release\ncarries the checksum-pinned\n[`liquilens-evidence-carrier-mcp-0.19.0.mcpb`](https://github.com/beepboop2025/liquilens-evidence-carrier/releases/download/v0.19.0/liquilens-evidence-carrier-mcp-0.19.0.mcpb)\nbundle for compatible desktop clients. Registry identity:\n[`io.github.beepboop2025/liquilens-evidence-carrier`](https://registry.modelcontextprotocol.io/v0.1/servers/io.github.beepboop2025%2Fliquilens-evidence-carrier/versions/0.19.0).\n\n<!-- mcp-name: io.github.beepboop2025/liquilens-evidence-carrier -->\n\n## Integration kit\n\n- [`docs/EVIDENCE-CARRIER-V1.md`](docs/EVIDENCE-CARRIER-V1.md) defines the\n  contract, rights routing, transports, and failure modes.\n- [`docs/FLEET-BRIEF-V1.md`](docs/FLEET-BRIEF-V1.md) defines deterministic,\n  rights-aware four-product briefs and their five explicit section states.\n- [`docs/TRADE-SAFETY-RECEIPT-V1.md`](docs/TRADE-SAFETY-RECEIPT-V1.md) defines\n  strict order, policy, evidence, broker-preview, receipt and verification\n  semantics; the companion adoption plan separates discovery from enforcement.\n- [`docs/TRADE-SAFETY-X402.md`](docs/TRADE-SAFETY-X402.md) defines optional paid\n  access, Bazaar discovery, durable replay/reconciliation, and activation gates;\n  [`docs/TRADE-SAFETY-TRACTION.md`](docs/TRADE-SAFETY-TRACTION.md) keeps reach,\n  activation, settlement, release, protected orders, payers, and revenue as\n  separate evidence layers.\n- [`CHANGELOG.md`](CHANGELOG.md), the\n  [`v0.19.0 publication receipt`](docs/RELEASE-0.19.0.md), the preserved\n  [`v0.18.0 receipt`](docs/RELEASE-0.18.0.md), and the unchanged\n  [`v0.17.1 recovery receipt`](docs/RELEASE-0.17.1.md) separate current release\n  facts from immutable history and independently versioned channels.\n- [`integrations/fdc3`](integrations/fdc3) contains the custom financial-desktop\n  context schema.\n- [`integrations/openlineage`](integrations/openlineage) contains the custom\n  lineage facet schema.\n- [`dbt_project.yml`](dbt_project.yml) and [`macros`](macros) make the repository\n  directly installable as a dbt package. The mirrored [`integrations/dbt`](integrations/dbt)\n  directory remains available for integration-bundle consumers.\n- [`protocol/verify_hash_tree_v1.mjs`](protocol/verify_hash_tree_v1.mjs) verifies\n  content identities without trusting Python number formatting.\n\n## Inherit verification in existing workflows\n\nPin the reusable action to an exact release tag:\n\n```yaml\n- uses: beepboop2025/liquilens-evidence-carrier@v0.19.0\n  with:\n    path: evidence/close.evidence.json\n```\n\nFor local commit gates, add this repository to `.pre-commit-config.yaml`. The\npublished hook verifies files ending in `.evidence.json` or `.carrier.json` and\npasses every matched file through `liquilens-evidence verify-files`.\n\n## Use in another product\n\n1. Issue the carrier at the boundary where the evidence and its rights are\n   known.\n2. Verify before every disclosure or conversion.\n3. Preserve the raw carrier plus `carrier_id` and `record_hash` at materialized\n   boundaries.\n4. Treat missing carrier metadata as a failure, not as permission to use a naked\n   number.\n5. Add a product-specific adapter and golden vector; do not fork the core\n   temporal or authority semantics.\n\n## Provenance and license\n\nProtocol artifact SHA-256 values are recorded in\n[`protocol/catalog.json`](protocol/catalog.json). The original carrier,\nreference, FDC3, and OpenLineage contracts retain their established identities;\nthe Fleet Brief and Trade Safety v1 schemas are additive. This public repository is the\nredistribution boundary for the carrier kit; private research code and datasets\nare not included.\n\nCode, schemas, documentation, and integration assets in this repository are\nlicensed under [Apache‑2.0](LICENSE). Provider data carried inside an evidence\nobject retains its own rights and license; this repository's license does not\ngrant rights to third-party data or product trademarks.\n",
  "bytes": 20296,
  "sha": "22bbd0282871886ba397b892945fb0a374926e99878306019439894cf9487a06",
  "repo_slug": "beepboop2025/liquilens-evidence-carrier",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_beepboop2025_liquilens_evidenc_2d225981/readme"
}