ravage

XBEN Run Evidence

This directory contains the published, reproducible evidence for Ravage’s full XBEN runs.

Each dated bundle separates reviewer-friendly reports from compressed raw artifacts. Start with that bundle’s START_HERE.md; extract the raw archive only when auditing transcripts, commands, target logs, or per-case databases.

Publication Note

The sealed 2026-07-12 raw archive is already public in this repository. It contains dead synthetic flags, disposable local-target authentication values, and complete solution traces. Do not supply it to an agent taking a future blind evaluation, and do not treat the recorded token-shaped scan as a guarantee that arbitrary raw evidence is safe to publish.

Some text inside the immutable evidence bundle recommends access-controlled storage. That is the conservative handling policy, but it does not describe the archive’s current public repository state. The bundle remains unchanged because its files are covered by the published integrity manifest. Future evidence releases should link redacted reviewer artifacts publicly and keep raw traces access-controlled by default.

The outer archives.sha256 authenticates the exact compressed archive. The inner raw-artifact manifest verifies the paths it names, but does not prove the absence of additional archive entries. The current archive also carries macOS AppleDouble metadata records. Future packaging should suppress operating-system metadata and verify a complete inventory, including unexpected paths.

Because the public archive includes solution traces, later comparisons on the same 104 cases cannot be assumed unseen even when they generate new randomized flags. Treat them as public-regression runs, isolate agent tools from public browsing, and use fresh or private variants for unseen-task claims.

Git Provenance

The run used source commit 358ceef1d11159f725ec1f355b098722a2fd7186; the evidence was first packaged at 099b0d3dfde6b93d67f984de79ffbf1357344d87. Pull request 4 was squash-merged to main as 9a7393444898f0324643d0e5c93923027298e5c5, so the first two commits are not ancestors of main. Preserve them with durable tags before deleting the launch-readiness-and-release branch. The published checksums independently authenticate the evidence bytes present on main.